Qubes OS Security Bulletin 118: Dom0 arbitrary code execution via qvm-copy-to-vm error reporting
Summary
Qubes OS Security Bulletin 118 discloses a Dom0 arbitrary code execution vulnerability in the qvm-copy-to-vm error reporting path. An attacker could inject commands into dom0 via a crafted remote filename if a user copies to a compromised qube; patch qubes-core-dom0-linux 4.3.22 is available for dom0, and all releases are affected. VM variant is not affected; users should update via Qubes Update and verify signatures per the bulletin.