CVE-2026-82636: OS Command Injection
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed?
Qubes OS installations running qubes-core-dom0-linux before version 4.3.22 are affected. The vulnerable path is a qvm-copy-to-vm operation initiated from dom0 and targeting an attacker-controlled qube.
What does exploitation require?
An attacker needs control of the destination qube and must induce a qvm-copy-to-vm operation from dom0. Exploitation also requires user interaction, as reflected by the UI:R vector, and depends on shell metacharacters reaching an error message processed by the system library function.
What is the potential impact?
Successful exploitation can result in OS command injection in the affected workflow. The supplied vector indicates high confidentiality, integrity, and availability impact, with scope changed.
How can I determine whether I am affected?
Check the installed qubes-core-dom0-linux version. Versions earlier than 4.3.22 are affected; version 4.3.22 is not identified as affected by the provided information.