Hacker News
Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
A flaw in the `qvm-copy-to-vm` tool allows a compromised qube to inject an arbitrary command into dom0 via the error-reporting backchannel, where the filename returned by the qube is displayed in a GUI dialog using `system()`. The vulnerability stems from insufficient sanitisation of the remote filename, enabling code execution when a user copies a file from dom0 to the malicious qube. Updating dom0 with the provided patches mitigates the issue.