Web appOpen in Telegram
QQubes OS

Qubes OS

✅ High trust
@QubesOS · channel · Education · indexed since 2026-05-17
1 385subscribers+8 in a week
159average post reach
11.5%ER — reach to subscribers
15posts in 30 days
Qubes OS
All previous messages missed for an entire year has been recovered and posted here. Sorry for any inconveniences.
312 ·
Qubes OS
Qubes OS Summit 2026: Proposals closing soon; tickets still available! https://www.qubes-os.org/news/2026/08/22/qubes-os-summit-2026-proposals-closing-soon-tickets-still-available/ As previously announced (https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/), the call for proposals (https://pretalx.com/qubes-os-summit-2026/cfp) for Qubes OS Summit 2026 (https://pretix.eu/qubes/summit2026/) will end on 2026-08-31. If you’d like to present at the Summit, please submit your proposal soon! As a reminder: You may present either on site or virtually from anywhere in the world. If your proposal is accepted and you wish to present in person, you’ll be issued an on-site ticket free of charge, no purchase necessary. If you select “Don’t record this session” when submitting your proposal, your presentation will not be livestreamed or recorded. Online attendees will not be able to view it. When and where Friday, October 30 @ 9:30 AM — Sunday, November 1 @ 3:00 PM (GMT+1) (A more specific schedule will be published after the speaker lineup is finalized.) Refugio Berlin (https://refugio.berlin/) Lenaustraße 3-4 12047 Berlin View on OpenStreetMap (https://www.openstreetmap.org/way/263350430) Attend in person or online There are three ways to attend the Summit: In person at Refugio Berlin (https://refugio.berlin/) Requires a paid on-site ticket (https://pretix.eu/qubes/summit2026/) Grants access to the hackathon (including interactive workshops) and any design sessions (depending on conference schedule) Provides the opportunity to socialize, network, and mingle with like-minded individuals who are passionate about secure computing Grants exclusive access to any non-livestreamed, non-recorded presentations (see below) Grants access to attend presentations and participate as a live audience member Actively participate online Requires a free virtual
256 ·
Qubes OS
QSB-117: Intel CPU firmware vulnerabilities https://www.qubes-os.org/news/2026/08/28/qsb-117/ We have published Qubes Security Bulletin (QSB) 117: Intel CPU firmware vulnerabilities (https://github.com/QubesOS/qubes-secpack/blob/2fae4b5eb43fae0b3bd58cc50444aac283d702fb/QSBs/qsb-117-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions. Qubes Security Bulletin 117 ---===[ Qubes Security Bulletin 117 ]===--- 2026-08-28 Intel CPU firmware vulnerabilities User action ------------ Continue to update normally [1] in order to receive the security updates described in the "Patching" section below. No other user action is required in response to this QSB. Summary -------- On 2026-08-11, Intel published "microcode-20260811 Release," [3] which is associated with several Intel security advisories. Among these security advisories, we suspect the following may apply to Qubes OS: - "2026.3 IPU, Intel Processor Load Value Injection Zero Data Advisory" (INTEL-SA-01423) [4] - "Intel Processor Firmware Advisory - 01428" (INTEL-SA-01428) [5] - "Intel Processor Firmware Advisory - 01435" (INTEL-SA-01435) [6] - "2026.3 IPU, Intel Processor Firmware Advisory" (INTEL-SA-01441) [7] - "2026.3 IPU, Intel Xeon Processor Firmware Advisory" (INTEL-SA-01442) [8] Unfortunately, these advisories do not provide sufficient information for us to make a definitive assessment about the extent to which these vulnerabilities affect the security of Qubes OS. Based on the limited information available, we cannot exclude possibility of a cross-qube attack. Impact ------- On affected systems, an attacker who has managed to compromise one qube can attempt to exploit these vulnerabilities in order to infer data belonging to other qubes or escalate their privileges. Affected systems ----------------- O
127 ·
[7] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html [8] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html [9] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/blob/main/releasenote.md#microcode-20260812 -- The Qubes Security Team https://www.qubes-os.org/security/ Source: qsb-117-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/2fae4b5eb43fae0b3bd58cc50444aac283d702fb/QSBs/qsb-117-2026.txt) Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmqSEC8ACgkQ1lWk8hgw 4Go3Xw/+LdLu3Dx+S1iH8YDpk2Ef2WJwXNl+Msmt+cTntk/wdEvsAeRWc0/t85fZ ySfiYIAq+PvED2G7rSbVmgqWp3sPNCaSS89Penr3praoLfxRxLc23HbLQrabnKgK 2TNRiFlk+OSqvjqvItn/y+kyxB4TZAnNtDHu9Eins/B0gVAz+P//aSFVOb42UTo9 7gLNWpW1CxflQqKfNnEqxah5m2iH72pMzir6F8fXC9JFMp1PWcvn1cRfKHrAs3lw qw7kUz2mByT1qHIMs/iQ6PA4bOhlo0km1M+z+sFhyXNvsdz2JlAnlViX7ZOCCxrb YoJd/VPnaH9xtUUh++iDmtIyylxTlx7vmOb/WEefucD+EH7zM5x3BdKb7M0vpKgy vJU3a5+pY90opla7hT8GWVuIpzhBSLQlhR4RNLWSdu+pQeWqUPG2rapww0B3/Hia t98H76iMMCDvy74Bj+hChrO95wgY35JJveSXF51WiJmOjofxFeyxgTBrlcjlmpkb kUybNm8fm9LZAOG6zFJIYJN0q0+tKu0qc4Z1cU+EIIL6G5msMUIMKXV3Tg/KpUW/ Yo3dGYUUTVCsmKtaXw9ASRvnaHS3ADC6wRZK5XSkqsXNVoQI0sWkik5vn0VvS+LW VdOSWdoQGJRAAEpRmM/grsxgqq3Sn+Tck2g3IcgK+aRysClb6z8= =Xehb -----END PGP SIGNATURE----- Source: qsb-117-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/2fae4b5eb43fae0b3bd58cc50444aac283d702fb/QSBs/qsb-117-2026.txt.sig.marmarek) Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqSEywACgkQSsGN4REu FJDCww//aucPqi/Fujn0/aVD2zSwNw9+b+8KulNRODaP86MaNu9kUs6+TNIOvGOx egeJim/vCIbdehCzd2x1+GKonmtlQzHTFE3VKCJXQ7u74/fa2cSIZwmjjwdjhbgs 78m4grmdsW4UtQGBEku6M4Nl4vYDjbw3orCwONf4rqOG8dsHK0REJnBnXTeq6aAo Q/3NfuE5b
130 ·
A PGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP) standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG) (https://gnupg.org/). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures. Why should I care whether a QSB is authentic? A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project. How do I verify the PGP signatures on a QSB? The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software).) Obtain the Qubes Master Signing Key (QMSK), e.g.: $ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc gpg: directory '/home/user/.gnupg' created gpg: keybox '/home/user/.gnupg/pubring.kbx' created gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc' gpg: /home/user/.gnupg/trustdb.gpg: trustdb created gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported gpg: Total number processed: 1 gpg: imported: 1 (For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate
124 ·
QSB-118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting https://www.qubes-os.org/news/2026/08/29/qsb-118/ We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting (https://github.com/QubesOS/qubes-secpack/blob/f65082c8211a421ed15a59219d6e54e93289fafb/QSBs/qsb-118-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions. Qubes Security Bulletin 118 ---===[ Qubes Security Bulletin 118 ]===--- 2026-08-28 Dom0 arbitrary code execution in qvm-copy-to-vm error reporting User action ------------ Continue to update normally [1] in order to receive the security updates described in the "Patching" section below. No other user action is required in response to this QSB. Summary -------- If `qvm-copy-to-vm` is used to copy a file from dom0 to a malicious qube, that qube can inject an arbitrary command into dom0. Impact ------- If an attacker has compromised a qube, and if the user initiates a `qvm-copy-to-vm` call from dom0 to the compromised qube, then the attacker can exploit this vulnerability in order to inject an arbitrary command into dom0, which allows the attacker to take control of Qubes OS. Technical details ------------------ The `qvm-copy-to-vm` tool allows copying files from dom0 to a specified qube. It uses the "qfile" protocol, which is a simplified archive format, including simple file metadata (much simpler than `tar` or `cpio`). The protocol also includes transfer confirmation at the end, which is sent by the target back to the source. This confirmation includes a checksum of all the transferred files, an error code (if any), and the name of the last received file. In the case of an error, as reported by the error code field, dom0 displays a GUI message that includes the error information and the
150 ·
27 program_invocation_short_name, buf, strerror(errno)) < 0) { 28 fprintf(stderr, "Failed to allocate memory for error message :(\n"); 29 return; 30 } 31 #undef KDIALOG_CMD 32 #undef ZENITY_CMD 33 fprintf(stderr, "%s\n", buf); 34 system(dialog_cmd); 35 } 36 37 _Noreturn void gui_fatal(const char *fmt, ...) { 38 va_list args; 39 va_start(args, fmt); 40 display_error(fmt, args); 41 va_end(args); 42 exit(1); 43 } The problem is that `sanitize_remote_filename()` removes only non-ASCII characters (and double quotation marks) but leaves shell meta-characters in place. Then, `system()` runs the constructed command, including the attacker-controlled name via the shell. Note that the VM variant of `qvm-copy-to-vm` is not affected, as its version of the error reporting function does not use `system()`: core-agent-linux/qubes-rpc/gui-fatal.c: 16 static void produce_message(const char *type, const char *fmt, va_list args) 17 { ... 31 if (progress_type && !strcmp(progress_type, "gui")) 32 { 33 switch (fork()) 34 { 35 case -1: 36 exit(1); // what else 37 case 0: 38 if (geteuid() == 0) { 39 if (setuid(getuid()) != 0) { 40 perror("setuid failed, not calling zenity/kdialog"); 41 exit(1); 42 } 43 } 44 fix_display(); 45 execlp("/usr/bin/zenity", "zenity", "--error", "--text", dialog_msg, NULL); 46 execlp("/usr/bin/kdialog", "kdialog", "--sorry", dialog_msg, NULL); 47 exit(1); 48 default:; 49 } 50 } 51 free(dialog_msg); 52 } 53 54 void gui_fatal(const char *fmt, ...) 55 { 56 va_l
158 ·
Q
jaJGgXzD/QntiNiWH1iaB7NxeZJPzKGg8O7MPUvQV4Cn02uoE5J5EY8XZrGhNPVl D4HHrQb+dMrwImEAGovHMdqVPJIiTGRFm5umwpKK8NRVWGjpsu8= =fHjz -----END PGP SIGNATURE----- Source: qsb-118-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/f65082c8211a421ed15a59219d6e54e93289fafb/QSBs/qsb-118-2026.txt.sig.marmarek) Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqSRk0ACgkQSsGN4REu FJC8wQ//UOa2EdMZpIDLaYropqMHyt7cVlm3Ad4zpgqmteWOUSS2z6Y3DLA2b0Ng xVDsmgJcoxqMt0tbzU9awSB/v41CKPQlXnevEFucwZWgeoQIhnZwr7c6zo2unngv wc2eMMsIL/7QX2DPotoieshryTUB6kbb1hKwiXojWOJKTwVvQPRZmU6hWLAXtg7G F4Ar/XMm2DR+KstIHFpvP+IWdS41+SWjIgjJJraUl5BE7mDF51M8vR4IvVM9Td8w bb1ENAFO2W/ZnYnqGJpMmzWVhDzxjkikH9TT3CZmdulXa7ggK2V2EgBDJ681XtW+ jOC9f5OJjoVHc5LtPsAMZxL3sGbfOBfogK5Fwpi6lmzjcG3oCB6MMvEkveZRaSiO H8vPl4H1dEIUKSA1LGZWEgY8RjuX0N4pnNOLzbn86tMpqYLtNBqGZ2/r8WkJSfXS fYWyVAtF9kcy8scb4lYlsdfD7gZ8wH7dl/iUKikiS3NyFdAlYvb0OZd6c7BZwD2C +YLHlo03he9WE1GbLoPPzqTN8VnunJ9eyyCs56SsHL5CYLfLnT95kMssAd+uJypo 7QZj3+xz7i2kaqK4osEL+5WUR47DyJEgKP8bMPeCV5ZZFC85eVKAn4BzYULx6tff wVin+t9uZ2kwur7IyG+8Bb1PUgr+vATsVW1QcrfcRT6ujY4VDDs= =1/K/ -----END PGP SIGNATURE----- Source: qsb-118-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/f65082c8211a421ed15a59219d6e54e93289fafb/QSBs/qsb-118-2026.txt.sig.simon) What is the purpose of this announcement? The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published. What is a Qubes security bulletin (QSB)? A Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/) is a security announcement issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team). A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address
241 ·
Q
Qubes OS
XSAs released on 2026-09-08 https://www.qubes-os.org/news/2026/09/08/xsas-released-on-2026-09-08/ The Xen Project (https://xenproject.org/) has released one or more Xen security advisories (XSAs) (https://xenbits.xen.org/xsa/). The security of Qubes OS is not affected. XSAs that DO affect the security of Qubes OS The following XSAs do affect the security of Qubes OS: (none) XSAs that DO NOT affect the security of Qubes OS The following XSAs do not affect the security of Qubes OS, and no user action is necessary: XSA-509 (https://xenbits.xen.org/xsa/advisory-509.html): Denial of service only. XSA-510 (https://xenbits.xen.org/xsa/advisory-510.html): Denial of service only. XSA-511 (https://xenbits.xen.org/xsa/advisory-511.html): Qubes OS does not use XSM silo. XSA-512 (https://xenbits.xen.org/xsa/advisory-512.html): Qubes OS does not use oxenstored. XSA-513 (https://xenbits.xen.org/xsa/advisory-513.html): Qubes OS does not use tapdisk. About this announcement Qubes OS uses the Xen hypervisor (https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview) as part of its architecture (https://doc.qubes-os.org/en/latest/developer/system/architecture.html). When the Xen Project (https://xenproject.org/) publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA) (https://xenproject.org/developers/security-policy/). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker (https://www.qubes-os.org/security/xsa/), which is a comprehensive list of all XSAs pu
166 ·
Qubes OS
Qubes Canary 048 https://www.qubes-os.org/news/2026/09/09/canary-048/ We have published Qubes Canary 048 (https://github.com/QubesOS/qubes-secpack/blob/f1378920daaaad3e338fa18aa972da074bc45aef/canaries/canary-048-2026.txt). The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement. Qubes Canary 048 ---===[ Qubes Canary 048 ]===--- Statements ----------- The Qubes security team members who have digitally signed this file [1] state the following: 1. The date of issue of this canary is September 09, 2026. 2. There have been 118 Qubes security bulletins published so far. 3. The Qubes Master Signing Key fingerprint is: 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494 4. No warrants have ever been served to us with regard to the Qubes OS Project (e.g. to hand out the private signing keys or to introduce backdoors). 5. We plan to publish the next of these canary statements in the first fourteen days of December 2026. Special note should be taken if no new canary is published by that time or if the list of statements changes without plausible explanation. Special announcements ---------------------- None. Disclaimers and notes ---------------------- We would like to remind you that Qubes OS has been designed under the assumption that all relevant infrastructure is permanently compromised. This means that we assume NO trust in any of the servers or services which host or provide any Qubes-related data, in particular, software updates, source code repositories, and Qubes ISO downloads. This canary scheme is not infallible. Although signing the declaration makes it very difficult for a third party to produce arbitrary declarations, it does not prevent them from using force or other means, like blackmail or compromising the signers' laptops, to coerce us
139 ·
corresponding qubes-secpack.git repo tags. [2] [2] Don't just trust the contents of this file blindly! Verify the digital signatures! Instructions for doing so are documented here: https://doc.qubes-os.org/en/latest/project-security/security-pack.html -- The Qubes Security Team https://www.qubes-os.org/security/ Source: canary-048-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/f1378920daaaad3e338fa18aa972da074bc45aef/canaries/canary-048-2026.txt) Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmqhJaEACgkQ1lWk8hgw 4GpAUA//dvesbc30xLrZ5hRrJgPBBOaMIXjLZk2il/EljKLAMLdPOk5Y01kNLLGS nvnLU0M5U8y1Oqlfj7WybABht8SrPSBg9gI1CrRvA69urz5V6VHDUsqAMhXozdLK FgT4+SuQfiAvlXOdjPljcZO4jWXWcQMWjecYTTiQdnMNC90VkrncYjNeioh6rhaL oCim2t5ynb9wpyo7zzG9KNDtDUzPSAphSZoJhb3PJXNOxHV6RLsyoz9b1wa1c3xp IJdS1EzMf/1/bmlZwg9FnLcGVOO/TdyOSKxP4d54SVt/JmYfpk2qAVfn/NWjlzVc LqcwebzGHQ56A4kyvc04PEuMzryneYDmxboKtwKUnOyMdnOxHtpbqh/jX6T/GodA wO8oJdoT5l1ugLfFK/sGluSx6FnFoczgukFxk+cIn3l38mEUAQLshWRNL3gk8LkW cKTFBBntwlV2XfmJBFhOM4s6N74RTrNhxWlsgT4LyOCcFRIT8CCLicmvmxSgjWJo v3p+pKqLNFe0GU64KUlt3Fvc0m4hyvxPZbmzA/UOevMzssX5BHkRXQDJaknLppy+ yZp/gfBX575wlgWn+khXPYQSIcHyEuZifZoMaGnfU0OgjPMcmC4SY9xQf2cH/dN+ gTyhd0+s9RfyWDdA2l1ZvG10t1Pz5SIJecPXHFMk+F6qHEpjezI= =wcFj -----END PGP SIGNATURE----- Source: canary-048-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/f1378920daaaad3e338fa18aa972da074bc45aef/canaries/canary-048-2026.txt.sig.marmarek) Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqhK+QACgkQSsGN4REu FJCzHQ//ejKjw9KcCp8EKE/pMMSeCHmIOBDqZFsM0Ifo4rzyCVc2TqLZ6K0JviuQ 5otz/lor5rI4Z1wCR4fZO7YwWHewaX7w7yILp6tRV+9el22lhWPJMl7BavjBK92d 8WUiuab0DrlxROUDtm62mgzQ5dHcqQjj/bZZhSeq/69e/L3OJsWclOdAOt+LjSUa rXYD+bB23PZh3FGdvW0znTLbs/0XpH
152 ·
Q
What are some signs of an unhealthy canary? Here is a non-exhaustive list of examples: Dead canary. In each canary, we state a window of time during which you should expect the next canary to be published. If no canary is published within that window of time and no good explanation is provided for missing the deadline, then the canary has died. Missing statement(s). Canaries include a set of numbered statements at the top. These statements are generally the same across canaries, except for specific numbers and dates that have changed since the previous canary. If an important statement was present in older canaries but suddenly goes missing from new canaries with no correction or explanation, then this may be an indication that the signers can no longer truthfully make that statement. Missing signature(s). Qubes canaries are signed by the members of the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team) (see below). If one of them has been signing all canaries but suddenly and permanently stops signing new canaries without any explanation, then this may indicate that this person is under duress or can no longer truthfully sign the statements contained in the canary. Does every unexpected or unusual occurrence related to a canary indicate something bad? No, there are many canary-related possibilities that should not worry you. Here is a non-exhaustive list of examples: Unusual reposts. The only canaries that matter are the ones that are validly signed in the Qubes security pack (qubes-secpack) (https://doc.qubes-os.org/en/latest/project-security/security-pack.html). Reposts of canaries (like the one in this announcement) do not have any authority (except insofar as they reproduce validly-signed text from the qubes-secpack). If the actual canary in the qubes-secpack is healthy, but reposts are late, absent, or modified on the website, mailing lists, forum, or social media platforms, you should no
212 ·
Qubes OS
QSB-119: Potential attacker-controlled format string in qvm-open-in-vm https://www.qubes-os.org/news/2026/09/15/qsb-119/ We have published Qubes Security Bulletin (QSB) 119: Potential attacker-controlled format string in qvm-open-in-vm (https://github.com/QubesOS/qubes-secpack/blob/2504a9d8fe7979eadaa933359da0981a3c14a7de/QSBs/qsb-119-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions. Qubes Security Bulletin 119 ---===[ Qubes Security Bulletin 119 ]===--- 2026-09-15 Potential attacker-controlled format string in qvm-open-in-vm User action ------------ Continue to update normally [1] in order to receive the security updates described in the "Patching" section below. No other user action is required in response to this QSB. Summary -------- Under certain circumstances (see "Technical details" below), if the user invokes qvm-open-in-vm (either directly or through the "Edit in disposable qube" GUI integration) on a file with an attacker-controlled filename or path, the attacker might be able to execute code in the qube in which the user invoked qvm-open-in-vm. Impact ------- An attacker who successfully exploits this vulnerability can take control over the qube in which the user invoked qvm-open-in-vm. Affected systems ----------------- All supported Qubes OS releases are affected. Among official Qubes OS templates, only Debian templates are affected. Technical details ------------------ When qvm-open-in-vm is invoked with a file (not an URI), the source-side part of the qrexec call is handled by the qopen-in-vm helper program. After sending the file content to the other side, qopen-in-vm tries to open a temporary file alongside the original file in order to save the response in case the user has edited the file in the target qube. If creating this file fails (e.g., becaus
110 ·
part of the file name in most cases. And even when they do control the full path, many users would likely find such a path suspicious, which would likely make it more difficult for an attacker to successfully trick the user into opening such a path. Discussion ----------- Normally, we do not issue Qubes security bulletins for purely "in-VM" vulnerabilities (like this one) that do not involve crossing the VM security boundary. However, we have decided to make an exception in this case, since this is a bug in our code and since qvm-open-in-vm is specifically intended to operate on untrusted input. While qvm-open-in-vm is designed to be hardened, keep in mind that handling less trusted data in a more trusted VM still can be risky for other reasons, for example: - Unsafe handling of attacker-controlled paths is an easy mistake to make in the shell. - A file explorer could render the thumbnail of an untrusted file with a buggy parser. - You might accidentally open the file with an application other than qvm-open-in-vm, exposing the full attack surface of that application. Patching --------- The following package contains the security update that addresses the vulnerability described in this bulletin: For Qubes 4.3, in affected templates and standalones: - qubes-core-agent version 4.3.48 This package will migrate from the security-testing repository to the current (stable) repository over the next two weeks after being tested by the community. [2] Once available, the package should be installed via the Qubes Update tool or its command-line equivalents. [1] In order for this security update to take effect, all affected templates must be updated with the package above, then shut down. Afterward, all qubes based on these templates (including disposables) must be restarted. All affected standalones must be updated with the package above. Credits -------- This vulnerability was first reported by Giulio Berra. Shortly after, it was independently repor
122 ·
Q
HEI0Vg2Gd3lAewa34zxicNsHlHh7OKsGFI027BxdIpZoEwbLzMThfA0+TH6t/JsN UEzh9lXD0cpuJIxHe0bSGrJL7kJN5CV9kztstr+YuH3lx52Blq7UAtw/8swvxvBB 8aFSeP8aXb9ldXuNtAxf581OmHAGmrxRpCOiQb0ehfBuNd6aQb+J29bjy1fc7F9e 9yaTlVk1cFSjKWCG/24IK2zz96sdWcoJMIE1FXNuwms4MAUNUFMPFqCT0keMeiqj yaJfWvXtoAJQPGrYClbC7D+VYKFYokBbB7c1nabpCzzuJ9uFXuQfHsb7PMYnAJh4 2PLat+BiUxiO3AATHtcrl4DEwRlu7RYW99EB3ax6WUDyxBAVWHnZ8NVoRLgj4bfr 7FJjE0wu8mKT3on0o6RLlifo7mXl1lmXZM6YcB1QD0+/zod0Q6c= =Zo3p -----END PGP SIGNATURE----- Source: qsb-119-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/2504a9d8fe7979eadaa933359da0981a3c14a7de/QSBs/qsb-119-2026.txt.sig.simon) What is the purpose of this announcement? The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published. What is a Qubes security bulletin (QSB)? A Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/) is a security announcement issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team). A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them. Why should I care about QSBs? QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally (https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html). However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs. What are the PGP signatures that accompany QSBs? A PGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP) standard. PGP signatures can be cryptograp
201 ·
Qubes OS
Qubes OS 4.3.2-rc1 is available for testing https://www.qubes-os.org/news/2026/09/18/qubes-os-4-3-2-rc1-available-for-testing/ The first release candidate (RC) for Qubes OS 4.3.2 is now available for testing. This patch release aims to consolidate all the security patches, bug fixes, and other updates that have occurred since the release of Qubes 4.3.1. What’s new in Qubes 4.3.2? Default Fedora template upgraded to Fedora 44 kernel-latest upgraded to Linux 7.2 Numerous bug fixes (https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20is%3Aclosed%20reason%3Acompleted%20type%3ABug%20label%3A%22affects-4.3%22%20closed%3A2026-06-11..2026-09-18%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22%20-label%3A%22C%3A%20website%22%20-label%3A%22C%3A%20infrastructure%22%20-label%3A%22C%3A%20tests%22) When is the stable release? That depends on the number of bugs discovered in this RC and their severity. As explained in our release schedule (https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html#release-schedule) documentation, our usual process after issuing a new RC is to collect bug reports, triage the bugs, and fix them. If warranted, we then issue a new RC that includes the fixes and repeat the process. We continue this iterative procedure until we’re left with an RC that’s good enough to be declared the stable release. No one can predict with certainty, at the outset, how many iterations will be required (and hence how many RCs will be needed before a stable release), but we tend to get a clearer picture of this as testing progresses. Since the changes between 4.3.1 and 4.3.2 are relatively minor, we currently don’t anticipate any major problems requiring a second RC. We currently expect to be able to publish the stable 4.3.2 release around the end of Septemb
175 ·
Q
View the full list of known bugs affecting Qubes 4.3 (https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20state%3Aopen%20type%3ABug%20label%3Aaffects-4.3%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22%20-label%3A%22C%3A%20website%22%20-label%3A%22C%3A%20infrastructure%22%20-label%3A%22C%3A%20tests%22) in our issue tracker (https://doc.qubes-os.org/en/latest/introduction/issue-tracking.html). What’s a release candidate? A release candidate (RC) is a software build that has the potential to become a stable release, unless significant bugs are discovered in testing. RCs are intended for more advanced (or adventurous!) users who are comfortable testing early versions of software that are potentially buggier than stable releases. You can read more about Qubes OS supported releases (https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html) and the version scheme (https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html) in our documentation. What’s a patch release? The Qubes OS Project uses the semantic versioning (https://semver.org/) standard. Version numbers are written as [major].[minor].[patch]. Hence, we refer to releases that increment the third number as “patch releases.” A patch release does not designate a separate, new major or minor release of Qubes OS. Rather, it designates its respective major or minor release (in this case, 4.3) inclusive of all updates up to a certain point. See our supported releases (https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html) for a comprehensive list of major and minor releases and our version scheme (https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html) documentation for more information about how Qubes OS releases
271 ·
Qubes OS
Qubes OS Summit 2026: Freedom of the Press Foundation and NovaCustom sponsorships; conference schedule available! https://www.qubes-os.org/news/2026/09/27/qubes-os-summit-2026-freedom-of-the-press-foundation-and-novacustom-sponsorships-conference-schedule-available/ We’re proud to announce two new Qubes OS Summit 2026 (https://pretix.eu/qubes/summit2026/) sponsorships: Freedom of the Press Foundation (FPF) (https://freedom.press/) as a Gold tier sponsor and NovaCustom (https://novacustom.com/) as a Silver tier sponsor!
2 · 156 ·
The FPF is a long-standing Qubes Partner (https://www.qubes-os.org/partners/). As a nonprofit organization, it is dedicated to supporting and defending public interest journalism. It leads the development of SecureDrop (https://securedrop.org/), an open-source whistleblower submission platform used by more than 50 media organizations around the world to securely accept documents from anonymous sources. FPF uses Qubes OS in the development of an integrated SecureDrop Workstation (https://github.com/freedomofpress/securedrop-workstation).
163 ·
Q
NovaCustom builds custom laptops, mini PCs, and smartphones with a focus on privacy, security, and customization. They offer the freedom of Dasharo coreboot firmware, true repairability, and a plethora of customization options. Several NovaCustom models are officially certified for Qubes OS (https://doc.qubes-os.org/en/latest/user/hardware/certified-hardware/certified-hardware.html). Conference schedule We’re also pleased to share the official conference schedule, including a list of sessions and speakers, which you can find here: https://pretalx.com/qubes-os-summit-2026/schedule/ (Please note that we’re still waiting on a few speakers to confirm their attendance, so this schedule is subject to change.) On-site tickets are nearly halfway sold out, so if you’d like to join us in person, we recommend getting your tickets soon! See below for details. When and where Friday, October 30 @ 9:30 AM — Sunday, November 1 @ 3:00 PM (GMT+1) Refugio Berlin (https://refugio.berlin/) Lenaustraße 3-4 12047 Berlin View on OpenStreetMap (https://www.openstreetmap.org/way/263350430) Attend in person or online There are three ways to attend the Summit: In person at Refugio Berlin (https://refugio.berlin/) Requires a paid on-site ticket (https://pretix.eu/qubes/summit2026/) Grants access to the hackathon (including interactive workshops) and any design sessions (depending on conference schedule) Provides the opportunity to socialize, network, and mingle with like-minded individuals who are passionate about secure computing Grants exclusive access to any non-livestreamed, non-recorded presentations (see below) Grants access to attend presentations and participate as a live audience member Actively participate online Requires a free virtual ticket (https://pretix.eu/qubes/summit2026/) For those who are presenting remotely For those who are attending presentations remotely and wish to ask questions or enga
177 ·
Qubes OS
Qubes OS 4.3.2 has been released! https://www.qubes-os.org/news/2026/10/02/qubes-os-4-3-2-has-been-released/ We’re pleased to announce the stable release of Qubes OS 4.3.2! This patch release aims to consolidate all the security updates and bug fixes that have occurred since the previous stable release. Our goal is to provide a secure and convenient way for users to install (or reinstall) the latest stable Qubes release with an up-to-date ISO. The ISO and associated verification files (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html) are available on the downloads (https://www.qubes-os.org/downloads/) page. Announcements Qubes OS Summit 2026 (https://pretix.eu/qubes/summit2026/) is coming up soon! This year’s Summit will take place from October 30 to November 1 in Berlin. As a reminder, Qubes 4.2 has reached end of life (EOL) (https://www.qubes-os.org/news/2026/06/21/qubes-os-4-2-has-reached-end-of-life/). If you’re still using Qubes 4.2, we urge you to upgrade to Qubes 4.3 (https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/upgrade/4_3.html) immediately. What’s new in Qubes 4.3.2? Default Fedora template upgraded to Fedora 44 kernel-latest upgraded to Linux 7.2 Security updates (https://www.qubes-os.org/security/qsb/) Numerous bug fixes (https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20is%3Aclosed%20reason%3Acompleted%20type%3ABug%20label%3A%22affects-4.3%22%20closed%3A2026-06-11..2026-09-18%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22%20-label%3A%22C%3A%20website%22%20-label%3A%22C%3A%20infrastructure%22%20-label%3A%22C%3A%20tests%22) For an overview of what’s new in Qubes 4.3, see the Qubes 4.3 release notes (https://doc.qubes-os.org/en/r4.3/developer/releases/4_3/release-notes.html
77 ·
Q
Fresh templates on a clean 4.3.2 installation are not affected. Users who perform an in-place upgrade from 4.2 to 4.3 (instead of restoring templates from a backup) are also not affected, since the in-place upgrade process already includes the above fix in stage 4. For more information, see issue #8701 (https://github.com/QubesOS/qubes-issues/issues/8701). View the full list of known bugs affecting Qubes 4.3 (https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20state%3Aopen%20type%3ABug%20label%3Aaffects-4.3%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22%20-label%3A%22C%3A%20website%22%20-label%3A%22C%3A%20infrastructure%22%20-label%3A%22C%3A%20tests%22) in our issue tracker (https://doc.qubes-os.org/en/latest/introduction/issue-tracking.html). What’s a patch release? The Qubes OS Project uses the semantic versioning (https://semver.org/) standard. Version numbers are written as [major].[minor].[patch]. Hence, we refer to releases that increment the third number as “patch releases.” A patch release does not designate a separate, new major or minor release of Qubes OS. Rather, it designates its respective major or minor release (in this case, 4.3) inclusive of all updates up to a certain point. See our supported releases (https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html) for a comprehensive list of major and minor releases and our version scheme (https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html) documentation for more information about how Qubes OS releases are versioned.
100 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count