There is a local user privilege exploit for the Linux kernel. Details are here:
http://isec.pl/vulnerabilities/isec-0021-uselib.txt
One thing to remember is that a local user does not mean that the user has to have access to the physical machine. It means that any user that can run code on the machine can gain root access.