In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 7b4881da5b19f65709f5c18c1a4d8caa2e496461 |
| n/a | n/a | v5.0.4 Build 20220216 |