Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for linux-2.6.
CVE-2008-2148[0]:
| The utimensat system call in Linux kernel 2.6.22 and other versions
| before 2.6.25.3 does not check file permissions when certain UTIME_NOW
| and UTIME_OMIT combinations are used, which allows local users to
| modify file times of arbitrary files, possibly leading to a denial of
| service.