A KVM guest using SEV-ES (Secure Encrypted Virtualization - Encrypted State) can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT using the exit reason SVM_EXIT_IOIO.
ccc3c93435dc2cf6f740404e0f3468344e1a65dc1fc33ad4cbde80538cdac73e