Update of Qubes OS 4.3.2, which uses virtualization for application isolation.

The release of the Qubes 4.3.2 operating system is now available, implementing the concept of using a hypervisor for strict isolation of applications and OS components (each class of applications and system services runs in separate virtual machines). For optimal performance, a system with 16 GB of RAM (minimum 6 GB) and a 64-bit Intel or AMD CPU supporting VT-x with EPT/AMD-v with RVI and VT-d or AMD IOMMU is recommended; ideally, an Intel GPU should be present (NVIDIA and AMD GPUs have not been sufficiently tested). The size of the installation image is 8 GB (x86_64).

Applications in Qubes are divided into classes based on the importance of the processed data and the tasks to be accomplished. Each application class (for example, work, entertainment, banking operations), along with system services (network subsystem, firewall, storage management, USB stack, etc.), operates in separate virtual machines, launched using the Xen hypervisor. These applications are accessible within a single desktop and are visually distinguished by different colored window borders. Each environment has read access to the underlying root filesystem and local storage, which does not overlap with the storage of other environments, with a special service facilitating interaction between applications.

Fedora and Debian package bases can serve as the foundation for forming virtual environments; the community also supports templates for Ubuntu, Gentoo, and Arch Linux. Access to applications in a Windows virtual machine can also be arranged, along with the creation of virtual machines based on Whonix to provide anonymous access through Tor. The user interface is built on Xfce. When a user launches an application from the menu, that application starts in a specific virtual machine. The content of the virtual environments is determined by a set of templates.

In the new version, the template for virtual environments has been updated to Fedora 44. The Linux kernel package has been updated to version 7.2. Accumulated bugs and vulnerabilities have been fixed, including critical vulnerabilities in the Xen hypervisor and a critical vulnerability in the 'qvm-copy-to-vm' utility that allows bypassing isolation and executing code at the Dom0 level.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster