# Qubes OS issues fix for Dom0 code-execution flaw

_Thursday, August 27, 2026 at 8:00 PM EDT · Security · Latest · Tier 1 — Major_

![Qubes OS issues fix for Dom0 code-execution flaw — Primary](https://www.qubes-os.org/attachment/icons/qubes-logo-icon-name-slogan-fb.png)

Qubes OS published Security Bulletin 118 for an arbitrary-code-execution vulnerability in Dom0, its administrative domain. A compromised qube can inject a command into Dom0 when a user copies a file from Dom0 to that malicious qube with qvm-copy-to-vm, the bulletin said. All Qubes OS releases are affected. Qubes identified qubes-core-dom0-linux version 4.3.22 for Qubes 4.3 as the update addressing the flaw; it will move from the security-testing repository to the stable repository after community testing.

## Sources

- [qubes-os.org](https://www.qubes-os.org/news/2026/08/29/qsb-118/)

---
Canonical: https://techandbusiness.org/newswire/airfJYYE7A_wjogr9jqPLi
Retrieved: 2026-08-30T15:28:32.662Z
Publisher: Tech & Business (techandbusiness.org)
