CVE-2016-10741: Debian Linux

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 4.9.3 (fixed in 4.9.3)

Published 2019-02-01. Last modified 2026-06-17.