Qubes OS Fixes a Flaw That Could Turn One File Copy Into Control of the Whole Machine

The Qubes OS project has disclosed a flaw in its own file-copy tool that it says can hand an attacker control of an entire machine, and has shipped a patch for it. Qubes Security Bulletin 118 is dated Aug. 28, 2026, and went up on the project's news page the following day.
Qubes OS is a desktop operating system that splits a user's work across isolated virtual machines, called qubes, and manages them from a single privileged one named dom0. The bulletin's summary reads: "If qvm-copy-to-vm is used to copy a file from dom0 to a malicious qube, that qube can inject an arbitrary command into dom0."
The impact, as the project describes it: an attacker who has already compromised a qube can use the flaw to "take control of Qubes OS," provided the user then starts a file copy from dom0 to that compromised qube. All Qubes OS releases are affected, the bulletin says, and the variant of the copy tool that runs inside a qube is not.
For Qubes 4.3, the fix ships as the dom0 package qubes-core-dom0-linux, version 4.3.22. As published, that package was in the project's security-testing repository, and the bulletin says it will move to the stable repository "after a short period of testing by the community." Users are told to keep updating normally; the bulletin says nothing else is required.
