Description
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
Published: 2026-08-30
Score: 7.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to inject operating‑system commands during a qvm‑copy‑to‑vm operation from dom0 to an attacker‑controlled qube. Because the core‑admin‑linux component calls the system library function to format an error message that can contain shell metacharacters, malicious input can be executed with dom0 privileges. Malicious execution would grant the attacker full control over the domain, enabling data theft, modification, or denial of service against the entire Qubes OS installation.

Affected Systems

Affected systems are Qubes OS installations running qubes‑core‑dom0‑linux versions earlier than 4.3.22. The flaw exists in the file copy agent component (qfile‑dom0‑agent.c) and is triggered only when dom0 performs a qvm‑copy‑to‑vm to a qube that an attacker can control. Thus, older Qubes OS releases and any deployment that allows untrusted qubes to invoke copy‑to‑vm from dom0 are vulnerable.

Risk and Exploitability

The CVSS score of 7.9 indicates high severity, but the EPSS score is not available, so the current exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector relies on the attacker gaining the ability to control or influence a qube and then executing a qvm‑copy‑to‑vm command from dom0. Successful exploitation would let a local attacker execute arbitrary commands with dom0 privileges.

Generated by OpenCVE AI on August 30, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Qubes OS update to version 4.3.22 or later to remove the vulnerability.
  • Limit the use of qvm‑copy‑to‑vm from dom0 to only trusted qubes to reduce the attack surface.
  • Review custom Qubes extensions that may invoke the system function during error handling and adjust or disable those paths.

Generated by OpenCVE AI on August 30, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection via qvm-copy-to-vm in Qubes OS

Sun, 30 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Description Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-30T13:05:46.409Z

Reserved: 2026-08-30T13:05:45.855Z

Link: CVE-2026-82636

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T14:17:03.310

Modified: 2026-08-30T14:17:03.310

Link: CVE-2026-82636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T15:45:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')