Impact
The vulnerability allows an attacker to inject operating‑system commands during a qvm‑copy‑to‑vm operation from dom0 to an attacker‑controlled qube. Because the core‑admin‑linux component calls the system library function to format an error message that can contain shell metacharacters, malicious input can be executed with dom0 privileges. Malicious execution would grant the attacker full control over the domain, enabling data theft, modification, or denial of service against the entire Qubes OS installation.
Affected Systems
Affected systems are Qubes OS installations running qubes‑core‑dom0‑linux versions earlier than 4.3.22. The flaw exists in the file copy agent component (qfile‑dom0‑agent.c) and is triggered only when dom0 performs a qvm‑copy‑to‑vm to a qube that an attacker can control. Thus, older Qubes OS releases and any deployment that allows untrusted qubes to invoke copy‑to‑vm from dom0 are vulnerable.
Risk and Exploitability
The CVSS score of 7.9 indicates high severity, but the EPSS score is not available, so the current exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector relies on the attacker gaining the ability to control or influence a qube and then executing a qvm‑copy‑to‑vm command from dom0. Successful exploitation would let a local attacker execute arbitrary commands with dom0 privileges.
OpenCVE Enrichment