Description of problem: The array allocated in init_state() is not large enough. It is possible to write past the end of the allocated memory.
Proposed upstream patch: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=91b80969ba466ba4b915a4a1d03add8c297add3f
Created attachment 315754 [details] Upstream patch for this issue
Created attachment 315826 [details] Proposed backported patch for MRG kernel
patch queued for -79
This was addressed via: MRG Realtime for RHEL 5 Server (RHSA-2008:0857)