ecryptfs throughout 2.6.28 wrote sensitive kernel memory to files that could potentially be read by users.
CVE-2009-0787 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0787): The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory.