Technology
QubesOS security bulletin details Dom0 code execution vulnerability
A flaw in the error reporting backchannel for file transfers could allow a compromised qube to execute commands in Dom0.
The short version
- Qubes OS released Security Bulletin 118 detailing an arbitrary code execution vulnerability affecting Dom0.
- The vulnerability occurs when copying a file from dom0 to a compromised qube, allowing the qube to inject arbitrary commands through file-transfer error handling.
- Users are advised to run standard updates to receive the patch, with no additional action required.
Key facts
- Qubes Security Bulletin (QSB) 118 outlines a Dom0 arbitrary code execution vulnerability in the qvm-copy-to-vm tool.[Hacker News]
- The issue stems from how filenames reported by target qubes during transfer errors are sanitized and passed to system dialog tools in dom0.[Hacker News]
- An attacker who has already compromised a target qube can take full control of Qubes OS if a user initiates a qvm-copy-to-vm command from dom0 to that qube.[Hacker News]
- Qubes OS developers stated that standard system updates will deliver the required security fixes to affected installations.[Hacker News]