Local user sets world-writable 0666 permissions on /dev/kvm (LPE via Januscape)

Detects attempts to grant world-writable (0666) permissions to the /dev/kvm device node using chmod or setfacl, or unauthorized (non-root) accounts interacting directly with the device. Such configuration changes are associated with the Januscape (CVE-2026-53359) vulnerability, which allows local users to exploit a shadow MMU use-after-free in the kernel to escalate privileges to root or escape into the host from a virtualized environment.