Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

·Hacker News··

We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instru...

Read full article →

Related Articles

Hackers Got Inside a Flock Camera
driverdan · Hacker News · 15h ago
Apple Reference Image: A New Approach for Verified Photography
imwally · Hacker News · 1d ago
Xiaomi Mimo 2.6 live post-training dashboard
krackers · Hacker News · 8h ago
Training a 4B model to produce 81% faster query plans than Postgres
polyphilz · Hacker News · 9h ago
Nvidia announces native GPU programming in Rust
nonmaskable · Hacker News · 17h ago