Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/NUS-Curiosity/KernJC
- https://github.com/ostrichxyz7/kexps