QubesOS flaw lets a malicious qube run arbitrary code in dom0 via qvm-copy-to-vm error reporting

Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

Qubes Security Bulletin 118 discloses a critical vulnerability in qvm-copy-to-vm's error reporting. When copying a file from dom0 to a compromised qube, the qube can inject shell commands into dom0 by crafting a malicious filename. The flaw lies in insufficient sanitization: only non-ASCII characters and double quotes are stripped, leaving shell metacharacters intact, which are then passed to system() in the dom0 error dialog. All Qubes OS releases are affected; the fix is in qubes-core-dom0-linux 4.3.22. Discovered by Tim C., the vulnerability allows full takeover of Qubes OS.

The problem is that sanitize_remote_filename() removes only non-ASCII characters (and double quotation marks) but leaves shell meta-characters in place.
  1. msm_

    Wow, this is serious. Makes you think, that even though QubesOS attack surface is so tiny (well-designed to be secure) there are still vulnerabilities to be found.

    Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0:

    >Note that the VM variant of `qvm-copy-to-vm` is not affected, as its

    version of the error reporting function does not use `system()`:

    Since you should not use Dom0 for regular work, and definitely not for interacting with likely-to-be-infected VMs, the scope of this attack is smaller than it sounds. On the flip side, when it works, it elevates privileges straight to Dom0.

  2. grommz

    The founder Joanna Rutkowska left QubesOS in 2018. All the code involved in this bug was committed by her successor Marek Marczykowski-Górecki.

    Joanna seems to be a genuine good guy, she once wrote a paper titled "Intel x86 considered harmful". That's why Huawei and the Chinese government aren't even trying any more to make western CPU architectures secure, it's a hopeless cause.

  3. sdcfgy

    Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

  4. user_7832

    Mini tangent: Could someone explain to me why Qubes is used for security, when (from what I understand) Jails on BSD is significantly more robust/safe/has a much smaller exposed area? Is it just "everyone's using linux already; here's a safer linux"?

  5. zby

    I am still impressed by QubesOS track and I use it for my dedicated 'financials' laptop.

    IMHO the thing that is holding back QubesOS is the lack of hardware acceleration for graphics - maybe now when dual monitor setups are getting popular this could be a workaround for the security considerations?

More from this day

2026-08-30