The Firewire device enabled by default in the GENERIC kernel for DragonFlyBSD defines an IOCTL function which can be malicious called passing a negative buffer length value. This value will bypass the length check (because the value is negative) and will be used in a copyout operation. This is a kernel bug and the system can be compromised by local users and important system information can be disclosed.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/52196/dragonflybsd-firewire.txt
Source: https://packetstormsecurity.com/files/52196/dragonflybsd-firewire.txt.html

