Skip to main content
Back to Newswire
Security

Qubes OS issues fix for Dom0 code-execution flaw

Qubes OS issues fix for Dom0 code-execution flaw Image: Primary
Qubes OS published Security Bulletin 118 for an arbitrary-code-execution vulnerability in Dom0, its administrative domain. A compromised qube can inject a command into Dom0 when a user copies a file from Dom0 to that malicious qube with qvm-copy-to-vm, the bulletin said. All Qubes OS releases are affected. Qubes identified qubes-core-dom0-linux version 4.3.22 for Qubes 4.3 as the update addressing the flaw; it will move from the security-testing repository to the stable repository after community testing.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from qubes-os.org and reviewed by the T&B editorial agent team.
Back to Newswire