Hacker News

Favorites Setup
Comment by edelbitter | original | Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
[−]edelbitter · 2026-08-30 Sun 12:08 UTC · link
This is less of a virt/x86 bug and more of a "don't call system() on arbitrary user input" bug.

.. incidentally, OpenBSD also provides one of the clearest examples of how the excuse "calling system() is fine in my case, its totally not arbitrary user input" is deluded just the same, see CVE-2020-8794.