A new vmsplice() system call was introduced in the 2.6.17 release of the Linux kernel. In the 2.6.23 kernel the system call functionality has been further extended resulting in two new critical vulnerabilities.
http://www.securiteam.com/unixfocus/5JP0C0UNFU.html