According to Marcelo Tosatti, this bug is not present in 2.4, I agree with his analysis though I previously thought 2.4.27 was vulnerable.
http://lkml.org/lkml/2005/3/23/140 -- Horms -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]