QSB-118: Dom0 Arbitrary Code Execution in qvm-copy-to-vm Error Reporting
摘要中文导览(来自条目评分时的双语摘要,基于原文提炼):
- Qubes 安全公告 QSB-118:从 dom0 用 qvm-copy-to-vm 向已被攻陷的 qube 拷贝文件时,目标 qube 可向 dom0 注入任意命令。链条是 qfile 协议在传输结束时由接收方回传含校验和、错误码与最后一个文件名的确认包;错误码非零时 dom0 弹窗显示错误信息与该文件名——pack.c 的 sanitize_remote_filename() 只把小于空格、大于 ~ 的字符和双引号替换为下划线,shell 元字符原样保留,下游 qfile-dom0-agent.c 的 display_error() 用 asprintf 把文件名拼进 kdialog/zenity 命令后直接 system() 执行。VM 侧同一功能不受影响,因为 gui-fatal.c 走 fork 而非 system()。值得记录的是它同时踩中两个经典模式:白名单写反成不完整的黑名单,以及在信任边界最敏感的一侧仍用 system() 拼字符串。
文章信息
- 作者: Qubes OS Project
- 发布: 2026-08-29
- 原文链接: https://www.qubes-os.org/news/2026/08/29/qsb-118/
- 标签:
dom0command-injectionsanitizationtrust-boundariessecurity
原文摘录(开头)
We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
---===[ Qubes Security Bulletin 118 ]===---
2026-08-28
Dom0 arbitrary code execution in qvm-copy-to-vm error reporting
User action
------------
Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.
Summary
--------
If `qvm-copy-to-vm` is used to copy a file from dom0 to a malicious
qube, that qube can inject an arbitrary command into dom0.
Impact
-------
If an attacker has compromised a qube, and if the user initiates a
`qvm-copy-to-vm` call from dom0 to the compromised qube, then the
attacker can exploit this vulnerability in order to inject an arbitrary
## Summary (EN)
QSB-118: copying files from dom0 to a compromised qube via qvm-copy-to-vm let the target inject arbitrary commands into dom0. The receiving side's confirmation packet includes the last filename; on error, dom0 displays it — but sanitize_remote_filename() only replaced characters below space, above ~, and double quotes, leaving shell metacharacters intact, and display_error() passed the filename through asprintf into a kdialog/zenity command run via system(). The VM-side equivalent was unaffected because it forks instead. The bulletin is a textbook double-hit: a whitelist inverted into an incomplete blacklist, plus string-concatenated system() at the most sensitive trust boundary.
## Obsidian 证据摘录
入选自 Obsidian《ClawFeed 24小时高价值一览 · 2026-08-31》第4篇:净化函数写反 + system() 拼串的双重经典模式。