The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1549
http://www.securityfocus.com/bid/3418
http://www.iss.net/security_center/static/7267.php
http://archives.neohapsis.com/archives/bugtraq/2001-10/0057.html