Gentoo Linux Security Advisory GLSA 200804-16 – Sebastian Krahmer of SUSE reported an integer overflow in the expand_item_list() function in the file util.c which might lead to a heap-based buffer overflow when extended attribute (xattr) support is enabled. Versions less than 2.6.9-r6 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65596/glsa-200804-16.txt
Source: https://packetstormsecurity.com/files/65596/Gentoo-Linux-Security-Advisory-200804-16.html

