The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.