It seems this issue is still unfixed in KVM-70. See https://bugzilla.redhat.com/show_bug.cgi?id=433560 Jay Turner writes: Ian Jackson discovered that accesses beyond end of qemu emulated disk devices can result in accesses to emulator's virtual memory space accesses and thus can allow user with sufficient privilege in guest (root, as this would need modification to kernel's driver) to break out of VM.
kvm-70-r1 is in the tree with this fix.
Thanks.