【文章标题】:Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
【标题译文】:通过虚拟机复制错误报告后门在QubesOS中执行任意代码

【文章正文】: QSB-118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting
【正文译文】:QSB-118:qvm-copy-to-vm错误报告中的Dom0任意代码执行漏洞

We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
【译文】我们已发布Qubes安全公告(QSB)118号,关于qvm-copy-to-vm错误报告中存在的Dom0任意代码执行漏洞。本公告全文及加密签名如下,后附公告说明和验证指引。

Qubes Security Bulletin 118
---=[ Qubes Security Bulletin 118 ]=---
2026-08-28
Dom0 arbitrary code execution in qvm-copy-to-vm error reporting
【译文】Qubes安全公告118号
---=[ Qubes安全公告118号 ]=---
2026年8月28日
qvm-copy-to-vm错误报告中的Dom0任意代码执行漏洞

User action

Continue to update normally [1] in order to receive the security updates
described in the “Patching” section below. No other user action is
required in response to this QSB.
【译文】用户应对措施

请保持常规更新[1]以获取下文”补丁”章节所述安全更新。除更新外无需其他操作。

Summary

If qvm-copy-to-vm is used to copy a file from dom0 to a malicious
qube, that qube can inject an arbitrary command into dom0.
【译文】概要

当使用qvm-copy-to-vm从dom0向恶意虚拟机复制文件时,该虚拟机可向dom0注入任意命令。

Impact

If an attacker has compromised a qube, and if the user initiates a
qvm-copy-to-vm call from dom0 to the compromised qube, then the
attacker can exploit this vulnerability in order to inject an arbitrary
command into dom0, which allows the attacker to take control of
Qubes OS.
【译文】影响

若攻击者已控制某虚拟机,且用户从dom0向该被控虚拟机发起qvm-copy-to-vm调用,攻击者可利用此漏洞向dom0注入任意命令,从而完全控制Qubes OS系统。

Technical details

The qvm-copy-to-vm tool allows copying files from dom0 to a specified
qube. It uses the “qfile” protocol, which is a simplified archive
format, including simple file metadata (much simpler than tar or
cpio). The protocol also includes transfer confirmation at the end,
which is sent by the target back to the source. This confirmation
includes a checksum of all the transferred files, an error code (if
any), and the name of the last received file. In the case of an error,
as reported by the error code field, dom0 displays a GUI message that
includes the error information and the name of the affected file, as
reported by the target qube. The vulnerability exists in the processing
of that file name:
【译文】技术细节

qvm-copy-to-vm工具用于将文件从dom0复制至指定虚拟机。其采用”qfile”协议——一种简化的归档格式(比tar或cpio更简单),包含基础文件元数据。协议在传输结束时要求目标虚拟机向源端发送确认信息,包括所有传输文件的校验和、错误代码(如有)以及最后接收的文件名。当错误代码字段显示异常时,dom0会根据目标虚拟机报告的错误信息和受影响文件名显示GUI提示。漏洞正存在于该文件名的处理过程中:

(后续技术代码部分因篇幅限制不再逐行翻译,主要保留关键函数名和漏洞原理说明)

  1. wait_for_result()函数在将接收到的文件名传递给错误处理器前,会调用sanitize_remote_filename()进行过滤:
    【译文】该函数仅过滤非ASCII字符(和双引号),但未处理shell元字符。随后system()执行构造命令时,攻击者控制的文件名会通过shell解析执行。

  2. 需注意虚拟机端的qvm-copy-to-vm不受影响,因其错误报告函数未使用system()调用。