A vulnerability in the Qubes OS allows bypassing isolation and executing code at the Dom0 level.

Information has been published regarding a vulnerability in the Qubes operating system, which uses a hypervisor for strict isolation of applications and OS components (each application class and system service operates in separate virtual machines). If an attacker compromises one of the virtual machines, the vulnerability allows them to bypass isolation, achieve arbitrary command execution on the host environment (Dom0), and gain control over the entire operating system. The issue arises when a user utilizes the 'qvm-copy-to-vm' utility to transfer a file from the host environment to a virtual machine controlled by the attacker. The vulnerability has been addressed in the qubes-core-dom0-linux package update 4.3.22.

The issue is present in the 'qvm-copy-to-vm' utility and is caused by improper error handling returned when accessing the virtual machine. The essence of the vulnerability is that the qvm-copy-to-vm utility launches kdialog or zenity to display error information, using the system() function and inserting details about the failed copy attempt in the command-line options. The cleaning of the file name is limited to stripping non-ASCII characters and double quotes without checking for the presence of special characters interpreted by the shell, such as '`' and '$'.

After the file copying process from the host system is completed, the handler on the virtual machine side sends back a confirmation of the operation, which includes the name of the last received file among other details. The attack consists of returning an error code instead of a confirmation and specifying the name of the file that failed to copy, including special characters processed by the command interpreter. Upon receiving the error, the handler on the host environment will execute the dialog utility with the error text using the system() command, passing in the command-line the file name returned by the attacker (for example, specifying 'file`id`' will result in the execution of the id command on the host).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster