Tech News
← Home  ·  All topics

Qubesos

1 GoKawiil brief on this topic

Qubes OS patches Dom0 code execution flaw in qvm-copy-to-vm tool

Qubes OS disclosed QSB 118, a vulnerability in the qvm-copy-to-vm utility that lets a compromised qube inject arbitrary commands into dom0 when a user copies files to it. The flaw stems from insufficient sanitization of a file name reported back through the qfile protocol's error-reporting mechanism, which dom0 displays without properly neutralizing malicious content. Users are advised to update normally to receive the fix, with no other action required.