I'm sharing one of my Kernel Driver IOCTL Fuzzer which operates completely from user land. To run this script you should know at least one process which sends IOCTL to your the device you are fuzzing.
read more.....http://www.debasish.in/2014/03/in-memory-kernel-driverioctlfuzzing.html
read more.....http://www.debasish.in/2014/03/in-memory-kernel-driverioctlfuzzing.html