SECURITY·중요도 9·2026. 08. 31.·GeekNews

Qubes OS의 copy-to-VM 오류 보고 백채널을 통한 임의 코드 실행

── KO ──────────────────

Qubes OS에서 copy-to-VM 취약점으로 dom0 장악 가능성 발생.

Qubes OS의 qube에 대한 copy-to-VM 기능에서 QSB-118 취약점이 발견되었습니다. 이미 손상된 qube에 도메인 0인 dom0에서 파일을 복사할 경우, 공격자가 파일명에 명령을 삽입하여 dom0를 장악할 수 있는 위험이 있습니다. 이 취약점은 비ASCII 문자와 큰따옴표를 제거한 파일명에 영향을 받습니다.


── EN ──────────────────

Vulnerability in Qubes OS allows attackers to exploit copy-to-VM for dom0 takeover.

A vulnerability in Qubes OS known as QSB-118 has been identified in the copy-to-VM feature. If an attacker starts copying files from dom0 to a compromised qube, they can insert commands into the filename, potentially leading to the takeover of dom0. This vulnerability affects filenames returned by the target qube that remove non-ASCII characters and double quotes.

원문 보기 →목록으로