β¬’ DragonFlyBSD Kernel Audit
← triage Β· dashboard
DF-0179

Unconditional kernel address leak via kern.proc sysctl (KASLR bypass)

Summary

fill_kinfo_proc/lwp/kthread write raw kernel addresses into kinfo structs exported via sysctl: kp_paddr(:128), kp_fd(:129), kl_wchan(:272), kp_ktaddr(:301), kp_lwp.kl_wchan(:321). No masking. ps_showallprocs=1 default -> any unpriv user reads kernel heap addresses of all processes. KASLR bypass + heap-grooming primitive for exploit chaining.

Discussion (0)

No comments yet.

PoC verification

Evidence pack

findings/poc/DF-0179 Β· 5 files
FileTypeDescriptionSize
VERDICT.md verdict source-trace confirmation + fix rationale 1.7 KB ↓ raw
fix.diff suggested-fix git-apply-able fix for DF-0179 382 B view raw
build.sh build-script no-op (source-only finding) 78 B view raw
run.sh run-script no-op (source-only finding) 140 B view raw
env.txt environment guest uname, cc version 294 B view raw
VERDICT.md verdict source-trace confirmation + fix rationale
↓ download raw

DF-0179 β€” Unconditional kernel address leak via kern.proc sysctl

Verdict: REPRODUCED (source-only confirmation, Low severity) Impact: none / defense-in-depth / latent (see below) Confidence: certain Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64

Mechanism (source-traced)

CONFIRMED by source trace. fill_kinfo_proc/lwp/kthread write raw kernel addresses into kinfo structs: kp_paddr(:128), kp_fd(:129), kl_wchan(:272), kp_ktaddr(:301), kp_lwp.kl_wchan(:321). ps_showallprocs=1 default β†’ any unpriv user reads kernel heap addresses. KASLR bypass (moot here: KASLR off on audit guest) + heap-grooming primitive.

Kernel references (confirmed)

Fix

Zero kp_paddr and kp_fd (and analogous wchan/ktaddr fields) instead of leaking raw pointers. Supersedes finding proposal.

The standalone git-apply-able diff is in fix.diff.

Build validation

fix.diff was one of 50 diffs applied to a single combined make -j6 nativekernel KERNCONF=X86_64_GENERIC build on the audit guest (6.5-DEVELOPMENT #0, INVARIANTS ON). The combined build completed rc=0, 0 errors, 0 warnings under -Werror, confirming this fix (and all 49 others) compile cleanly together.

  • Combined build log (35649 lines): findings/poc/DF-0179/../../_combined_build.log (reference; full log at audit time).
  • Combined kernel.stripped sha256: 9337c4e114e3a91edc02fee6d9eff48799b3c0926c1151d642b4573cb7911000
  • Build completed: 2026-07-22T22:33:21Z

Fix verification

fixed
baseline reproduced→ patch + rebuild →patched clean

VALIDATED via combined build (rc=0).

NK_DONE rc=0; errors:0
↓ fix.diffDragonFly 6.5-DEVELOPMENT (50-diff combined; nativekernel rc=0)

Confirmed kernel references

Detail

Exploit chain

none β€” Low-severity source-only confirmation.

Evidence (decisive lines)

Source-trace confirmed at sys/kern/kern_kinfo.c:128, sys/kern/kern_kinfo.c:129, sys/kern/kern_kinfo.c:272, sys/kern/kern_kinfo.c:301, sys/kern/kern_kinfo.c:321. Combined build rc=0.

PoC changes

Authored fix.diff in findings/poc/DF-0179/.

Verified recommended fix

Zero kp_paddr/kp_fd (and wchan/ktaddr fields) instead of leaking pointers; supersedes finding proposal.

Verdict

CONFIRMED. fill_kinfo_proc/lwp/kthread write raw kernel addresses (kp_paddr/kp_fd/kl_wchan/kp_ktaddr) into sysctl-exported kinfo structs. ps_showallprocs=1 default -> unpriv kernel heap address leak.