fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.
https://lists.launchpad.net/ecryptfs-devel/msg00011.html
https://lists.launchpad.net/ecryptfs-devel/msg00010.html
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.ubuntu.com/usn/usn-751-1
http://www.debian.org/security/2009/dsa-1787
http://www.debian.org/security/2009/dsa-1749
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html