CVE-2010-2530
NetBSD < 5.0.2 - Denial of Service via Negative Size in /dev/nsmb ioctl
Title source: llmDescription
Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION ioctl call.
References (4)
Core 4
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/07/12/6
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/41557
Various Sources x_refsource_confirm
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netsmb/smb_subr.c.diff?r1=1.34&r2=1.35&only_with_tag=MAIN&f=h
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/07/16/2
Scores
EPSS
0.0004
EPSS Percentile
12.8%
Details
CWE
CWE-189
Status
published
Products (40)
apple/mac_os_x
freebsd/freebsd
netbsd/netbsd
0.8
netbsd/netbsd
0.9
netbsd/netbsd
1.0
netbsd/netbsd
1.1
netbsd/netbsd
1.2
netbsd/netbsd
1.2.1
netbsd/netbsd
1.3
netbsd/netbsd
1.3.1
... and 30 more
Published
Sep 29, 2010
Tracked Since
Feb 18, 2026