The previous security errata (2.4.22-1.2173) unfortunatly contained a bug which made some systems unbootable, due to breakage in the aacraid scsi driver.
Paul Starzetz discovered a flaw in return value checking in mremap() in the Linux kernel versions 2.4.24 and previous that may allow a local attacker to gain root privileges.