- Sources: bulletin, discussion
- Summary: The bulletin states that the filename sanitiser replaces only non-printable characters and double quotes, leaving shell metacharacters intact, and that the dom0 error dialog is built into a string and run through system(). A compromised qube can therefore inject a shell command that dom0 executes when the user copies a file to that qube from dom0. All Qubes OS releases are affected, and the fix for Qubes 4.3 is qubes-core-dom0-linux 4.3.22, moving from security-testing to stable.
- Why it matters: Code execution in dom0 is a full compromise of a Qubes system, and the trigger is an ordinary file copy out of dom0.
- Follow-up: The bulletin names no CVE, so a tracking identifier needs picking up later.
send feedback on this story