← Latest briefing

Technology

QubesOS security bulletin details Dom0 code execution vulnerability

A flaw in the error reporting backchannel for file transfers could allow a compromised qube to execute commands in Dom0.

The short version

  • Qubes OS released Security Bulletin 118 detailing an arbitrary code execution vulnerability affecting Dom0.
  • The vulnerability occurs when copying a file from dom0 to a compromised qube, allowing the qube to inject arbitrary commands through file-transfer error handling.
  • Users are advised to run standard updates to receive the patch, with no additional action required.

Key facts

  • Qubes Security Bulletin (QSB) 118 outlines a Dom0 arbitrary code execution vulnerability in the qvm-copy-to-vm tool.[Hacker News]
  • The issue stems from how filenames reported by target qubes during transfer errors are sanitized and passed to system dialog tools in dom0.[Hacker News]
  • An attacker who has already compromised a target qube can take full control of Qubes OS if a user initiates a qvm-copy-to-vm command from dom0 to that qube.[Hacker News]
  • Qubes OS developers stated that standard system updates will deliver the required security fixes to affected installations.[Hacker News]

Sources