CVE-2016-10741
published 2019-02-01CVE-2016-10741: In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between…
PriorityP414medium4.7CVSS 3.0
AVLACHPRLUINSUCNINAH
EPSS
0.31%
23.2th percentile
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 4.9.6-1 (bookworm) | linux 4.9.6-1 (bookworm) |
| linux | linux_kernel | < 4.9.3 | 4.9.3 |
| linux | linux_kernel | >= 0 < 4.9.6-1 | 4.9.6-1 |
| linux | linux_kernel | >= 0 < 4.9.6-1 | 4.9.6-1 |
| linux | linux_kernel | >= 0 < 4.9.6-1 | 4.9.6-1 |
| linux | linux_kernel | >= 0 < 4.9.6-1 | 4.9.6-1 |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
vendor_redhat·2016-11-08·CVSS 4.7
CVE-2016-10741 [MEDIUM] CWE-369 kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
It was found that the Linux kernel can hit a BUG_ON() statement in the __xfs_get_blocks() in the fs/xfs/xfs_aops.c because of a race condition between direct and memory-mapped I/O associated with a hole in a file that is handled with BUG_ON() instead of an I/O failure. This allows a local unprivileged attacker to cause a system crash and a denial of service.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Ent
Debian
CVE-2016-10741: linux - In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause ...
vendor_debian·2016·CVSS 4.7
CVE-2016-10741 [MEDIUM] CVE-2016-10741: linux - In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause ...
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
Scope: local
bookworm: resolved (fixed in 4.9.6-1)
bullseye: resolved (fixed in 4.9.6-1)
forky: resolved (fixed in 4.9.6-1)
sid: resolved (fixed in 4.9.6-1)
trixie: resolved (fixed in 4.9.6-1)
GHSA
GHSA-vwf4-9qqv-87g9: In the Linux kernel before 4
ghsa_unreviewed·2022-05-14
CVE-2016-10741 [MEDIUM] CWE-362 GHSA-vwf4-9qqv-87g9: In the Linux kernel before 4
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
OSV
CVE-2016-10741: In the Linux kernel before 4
osv·2019-02-01·CVSS 4.7
CVE-2016-10741 [MEDIUM] CVE-2016-10741: In the Linux kernel before 4
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10741 kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
bugzilla·2019-02-01·CVSS 4.7
CVE-2016-10741 [MEDIUM] CVE-2016-10741 kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
CVE-2016-10741 kernel: race condition between direct and memory-mapped I/O in fs/xfs/xfs_aops.c
It was found that the Linux kernel can hit a BUG_ON() statement in the __xfs_get_blocks() in the fs/xfs/xfs_aops.c because there is a race condition possible between direct and memory-mapped I/O associated with a hole in a file that is handled with BUG_ON() instead of an I/O failure. This allows a local unprivileged attacker to cause a system crash and a denial-of-service.
References:
https://bugzilla.suse.com/show_bug.cgi?id=1124010
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.3
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04197b341f23b908193308b8d63d17ff23232598
Bugzilla
CVE-2016-4338 zabbix: mysql.size shell command injection
bugzilla·2016-12-15·CVSS 8.1
CVE-2016-4338 [HIGH] CVE-2016-4338 zabbix: mysql.size shell command injection
CVE-2016-4338 zabbix: mysql.size shell command injection
A possible shell command injection via mysql.size was found in zabbix when used with dash shell interepreter.
Upstream bug:
https://support.zabbix.com/browse/ZBX-10741
Reference:
http://seclists.org/bugtraq/2016/May/11
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04197b341f23b908193308b8d63d17ff23232598http://www.securityfocus.com/bid/106822https://bugzilla.suse.com/show_bug.cgi?id=1124010https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.3https://github.com/torvalds/linux/commit/04197b341f23b908193308b8d63d17ff23232598https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=04197b341f23b908193308b8d63d17ff23232598http://www.securityfocus.com/bid/106822https://bugzilla.suse.com/show_bug.cgi?id=1124010https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.3https://github.com/torvalds/linux/commit/04197b341f23b908193308b8d63d17ff23232598https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
2019-02-01
Published