Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION ioctl call.
AV:L/AC:L/Au:N/C:N/I:N/A:C
This vulnerability has a 0.30% probability of being exploited in the next 30 days, ranking higher than 21% of all scored CVEs.