CVE-2016-10150: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 10.2% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.

Affected products

  • Linux Linux Kernel: from 4.8.0, before 4.8.13 (fixed in 4.8.13)

Published 2017-02-06. Last modified 2026-06-17.