PT-2026-83556 · Qubes Os · Qubes Os
CVE-2026-82636
·
Published
2026-08-30
·
Updated
2026-08-30
CVSS v3.1
7.9
High
| Vector | AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qubes OS versions prior to 4.3.22
Description
OS command injection is possible during a
qvm-copy-to-vm call from dom0 to an attacker-controlled qube. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c because the system() library function is used to process an error message that may contain shell metacharacters, which are characters that can be used to change the meaning of a command in a shell environment.Recommendations
Update to version 4.3.22 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qubes Os