CVE-2010-2530

NetBSD < 5.0.2 - Denial of Service via Negative Size in /dev/nsmb ioctl

Title source: llm
STIX 2.1

Description

Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION ioctl call.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/07/12/6
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/41557
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/07/16/2

Scores

EPSS 0.0004
EPSS Percentile 12.8%

Details

CWE
CWE-189
Status published
Products (40)
apple/mac_os_x
freebsd/freebsd
netbsd/netbsd 0.8
netbsd/netbsd 0.9
netbsd/netbsd 1.0
netbsd/netbsd 1.1
netbsd/netbsd 1.2
netbsd/netbsd 1.2.1
netbsd/netbsd 1.3
netbsd/netbsd 1.3.1
... and 30 more
Published Sep 29, 2010
Tracked Since Feb 18, 2026