FreeBSD -- Kernel data leak via ptrace(PT_LWPINFO)
Not all information in the struct ptrace_lwpinfo is
relevant for the state of any thread, and the kernel does
not fill the irrelevant bytes or short strings. Since the
structure filled by the kernel is allocated on the kernel
stack and copied to userspace, a leak of information of the
kernel stack of the thread is possible from the debugger.
Some bytes from the kernel stack of the thread using
ptrace(PT_LWPINFO) call can be observed in userspace.
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright