← Back to events
ActiveTech

Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

Photo: Hacker News

What happened

We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instru...

Summary assembled by rule from the sources below

Why it's spreading

Sources