A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to bypass certain security restrictions. The security issue is caused due to the AACRAID driver not correctly checking the privileges for IOCTLs. This can be exploited to perform potentially dangerous operations by sending certain IOCTLs to the driver. The security issue is reported in versions prior to 2.6.23-rc2. Other versions may also be affected.
A patch to fix this issue can be found here, http://lkml.org/lkml/2007/7/23/195
This is already included in the 2.6.22.2 release.
linux kernel 2.6.22.2 is currently in a stable gentoo-sources release.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=719be62903a6e6419789557cb3ed0e840d3e4ca9