Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.
https://github.com/aquynh/capstone/commit/6fe86eef621b9849f51a5e1e5d73258a93440403