Skip to content
See the World Through Science

Qubes OS Fixes a Flaw That Could Turn One File Copy Into Control of the Whole Machine

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A Qubes OS desktop showing several terminal windows with differently coloured window borders arranged over a wallpaper carrying the Qubes cube logo.
A Qubes OS desktop. Each window's coloured border marks which isolated qube it belongs to; QSB-118 concerns dom0, the administrative domain that controls them all."Qubes OS ws 4-1-2" by DerekTDR, via wikimedia, CC0 · CC0

The Qubes OS project has disclosed a flaw in its own file-copy tool that it says can hand an attacker control of an entire machine, and has shipped a patch for it. Qubes Security Bulletin 118 is dated Aug. 28, 2026, and went up on the project's news page the following day.

Qubes OS is a desktop operating system that splits a user's work across isolated virtual machines, called qubes, and manages them from a single privileged one named dom0. The bulletin's summary reads: "If qvm-copy-to-vm is used to copy a file from dom0 to a malicious qube, that qube can inject an arbitrary command into dom0."

The impact, as the project describes it: an attacker who has already compromised a qube can use the flaw to "take control of Qubes OS," provided the user then starts a file copy from dom0 to that compromised qube. All Qubes OS releases are affected, the bulletin says, and the variant of the copy tool that runs inside a qube is not.

For Qubes 4.3, the fix ships as the dom0 package qubes-core-dom0-linux, version 4.3.22. As published, that package was in the project's security-testing repository, and the bulletin says it will move to the stable repository "after a short period of testing by the community." Users are told to keep updating normally; the bulletin says nothing else is required.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Qubes OS Fixes a Flaw That Could Turn One File Copy Into Control of the Whole Machine

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.