Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16552
http://www.securityfocus.com/bid/10640
http://www.rsbac.org/download/bugfixes/