kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute arbitrary code on the host machine.
{ "binaries": [ { "binary_name": "kvmtool", "binary_version": "0.20151104-1" } ] }
{ "binaries": [ { "binary_name": "kvmtool", "binary_version": "0.20170904-1" } ] }
{ "binaries": [ { "binary_name": "kvmtool", "binary_version": "0.20170904-1.1" } ] }