The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.