QubesOS flaw lets a malicious qube run arbitrary code in dom0 via qvm-copy-to-vm error reporting
Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
Qubes Security Bulletin 118 discloses a critical vulnerability in qvm-copy-to-vm's error reporting. When copying a file from dom0 to a compromised qube, the qube can inject shell commands into dom0 by crafting a malicious filename. The flaw lies in insufficient sanitization: only non-ASCII characters and double quotes are stripped, leaving shell metacharacters intact, which are then passed to system() in the dom0 error dialog. All Qubes OS releases are affected; the fix is in qubes-core-dom0-linux 4.3.22. Discovered by Tim C., the vulnerability allows full takeover of Qubes OS.
The problem is that sanitize_remote_filename() removes only non-ASCII characters (and double quotation marks) but leaves shell meta-characters in place.
- msm_
Wow, this is serious. Makes you think, that even though QubesOS attack surface is so tiny (well-designed to be secure) there are still vulnerabilities to be found.
Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0:
>Note that the VM variant of `qvm-copy-to-vm` is not affected, as its
version of the error reporting function does not use `system()`:
Since you should not use Dom0 for regular work, and definitely not for interacting with likely-to-be-infected VMs, the scope of this attack is smaller than it sounds. On the flip side, when it works, it elevates privileges straight to Dom0.
- grommz
The founder Joanna Rutkowska left QubesOS in 2018. All the code involved in this bug was committed by her successor Marek Marczykowski-Górecki.
Joanna seems to be a genuine good guy, she once wrote a paper titled "Intel x86 considered harmful". That's why Huawei and the Chinese government aren't even trying any more to make western CPU architectures secure, it's a hopeless cause.
- sdcfgy
Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582
- user_7832
Mini tangent: Could someone explain to me why Qubes is used for security, when (from what I understand) Jails on BSD is significantly more robust/safe/has a much smaller exposed area? Is it just "everyone's using linux already; here's a safer linux"?
- zby
I am still impressed by QubesOS track and I use it for my dedicated 'financials' laptop.
IMHO the thing that is holding back QubesOS is the lack of hardware acceleration for graphics - maybe now when dual monitor setups are getting popular this could be a workaround for the security considerations?