Qubes OS QSB 118: When Filenames Become Commands
Qubes Security Bulletin 118 exposes a subtle command-injection path in dom0’s qvm-copy-to-vm error handling. This walkthrough explains how attacker-controlled filename metadata reached system(), why direct process execution avoids the trap, and which dom0 package contains the Qubes 4.3 fix.