A vulnerability in Qubes OS allows for isolation bypass and code execution at the Dom0 level.

Information has been published about a vulnerability in the Qubes operating system, which uses a hypervisor for strict isolation of applications and OS components (each class of application and system service runs in separate virtual machines). If an attacker compromises one of the virtual machines, the vulnerability allows for bypassing isolation, executing arbitrary commands on the host environment (Dom0), and gaining control over the entire operating system. The issue manifests itself when a user uses the "qvm-copy-to-vm" utility to copy a file from the host environment to an attacker-controlled virtual machine. The vulnerability is fixed in the qubes-core-dom0-linux package update 4.3.22.

The issue exists in the "qvm-copy-to-vm" utility and is caused by improper handling of errors returned when accessing a virtual machine. The vulnerability stems from the fact that qvm-copy-to-vm would launch kdialog or zenity programs to display error information, using the system() function and substituting information about the unsuccessfully copied file as one of the command-line options. Filename sanitization was limited to stripping non-ASCII characters and double quotes, without checking for special characters interpreted by the command shell, such as "`" and "$."

After file copying from the host system is complete, the virtual machine handler sends back a confirmation of the operation, which, among other things, includes the name of the last file received. The attack consists of returning an error code instead of a confirmation and specifying a filename with special characters processed by the command interpreter for the file that failed to copy. After receiving an error, the host handler uses the system() command to launch a dialog box with the error text, passing the filename returned by the attacker on the command line (for example, specifying "file`id`" will run the id command on the host).

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster