2012-06-12 05:01:41 -04:00
|
|
|
---
|
2017-03-18 22:31:12 -04:00
|
|
|
layout: security
|
2015-10-13 23:31:03 -04:00
|
|
|
title: Security Bulletins
|
2017-03-18 22:31:12 -04:00
|
|
|
permalink: /security/bulletins/
|
2015-07-17 18:46:04 -04:00
|
|
|
redirect_from:
|
2017-03-18 22:31:12 -04:00
|
|
|
- /doc/security-bulletins/
|
2015-10-28 18:14:40 -04:00
|
|
|
- /en/doc/security-bulletins/
|
2015-10-11 03:04:59 -04:00
|
|
|
- /doc/SecurityBulletins/
|
2015-07-17 18:46:04 -04:00
|
|
|
- /wiki/SecurityBulletins/
|
|
|
|
- /trac/wiki/SecurityBulletins/
|
2012-06-12 05:01:41 -04:00
|
|
|
---
|
|
|
|
|
|
|
|
Qubes Security Bulletins
|
|
|
|
========================
|
|
|
|
|
2017-03-18 22:31:12 -04:00
|
|
|
Qubes Security Bulletins are published through the [Qubes Security Pack](/security/pack/).
|
2015-01-14 07:24:23 -05:00
|
|
|
|
2012-06-12 05:01:41 -04:00
|
|
|
2010
|
|
|
|
----
|
|
|
|
|
2012-06-15 06:36:15 -04:00
|
|
|
- None
|
|
|
|
|
2012-06-12 05:01:41 -04:00
|
|
|
2011
|
|
|
|
----
|
|
|
|
|
2015-05-08 09:17:21 -04:00
|
|
|
- [Qubes Security Bulletin \#01](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-001-2011.txt) (Gui daemon bug, Intel VT-d escape on non-IR hardware)
|
2012-06-12 05:01:41 -04:00
|
|
|
|
|
|
|
2012
|
|
|
|
----
|
2012-06-12 08:19:24 -04:00
|
|
|
|
2015-05-08 09:17:21 -04:00
|
|
|
- [Qubes Security Bulletin \#02](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-002-2012.txt) (Intel SYSRET bug)
|
|
|
|
- [Qubes Security Bulletin \#03](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-003-2012.txt) (Xen hypervisor bugs: XSA 13, others with DoS potential)
|
|
|
|
- [Qubes Security Bulletin \#04](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-004-2012.txt) (Qubes firewall misconfiguration: ipv6 allowed)
|
|
|
|
- [Qubes Security Bulletin \#05](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-005-2012.txt) (Xen hypervisor bugs: XSA 29, others with DoS potential)
|
2012-06-12 08:19:24 -04:00
|
|
|
|
2013-05-07 04:13:50 -04:00
|
|
|
2013
|
|
|
|
----
|
|
|
|
|
2015-05-08 09:17:21 -04:00
|
|
|
- [Qubes Security Bulletin \#06](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-006-2013.txt) (Xen hypervisor bugs: XSA 50, others with DoS potential)
|
|
|
|
- [Qubes Security Bulletin \#07](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-007-2013.txt) (Xen hypervisor bugs: XSA 57 potential escalation, also XSA 52-54 with potential leaks)
|
|
|
|
- [Qubes Security Bulletin \#08](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-008-2013.txt) (Xen hypervisor bugs: XSA 45,58 potential DoS)
|
2013-05-07 04:13:50 -04:00
|
|
|
|
2014-01-09 12:19:34 -05:00
|
|
|
2014
|
|
|
|
----
|
|
|
|
|
2015-05-08 09:17:21 -04:00
|
|
|
- [Qubes Security Bulletin \#09](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-009-2014.txt) (Qubes qvm-open-in-[d]vm environment inter-VM leak)
|
|
|
|
- [Qubes Security Bulletin \#10](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-010-2014.txt) (Qubes pulseaudio & vchan bugs, Xen XSA 87)
|
|
|
|
- [Qubes Security Bulletin \#11](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-011-2014.txt) (Qubes clipboard inter-VM leak)
|
|
|
|
- [Qubes Security Bulletin \#12](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-012-2014.txt) (Memory leak in Xen hypervisor via RDMSR emulation bug (XSA 108))
|
2015-01-14 07:30:07 -05:00
|
|
|
|
|
|
|
2015
|
|
|
|
----
|
|
|
|
|
2015-05-08 09:17:21 -04:00
|
|
|
- [Qubes Security Bulletin \#13](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-013-2015.txt) (Qubes Clipboard Timing Attacks and Qubes Core Python API Inconsistency)
|
|
|
|
- [Qubes Security Bulletin \#14](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-014-2015.txt) (Race condition in Qubes Inter-VM File-Copy Mechanism)
|
|
|
|
- [Qubes Security Bulletin \#15](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-015-2015.txt) (Critical Xen Hypervisor Vulnerability (XSA 109))
|
2015-10-30 01:51:23 -04:00
|
|
|
- [Qubes Security Bulletin \#16](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-016-2015.txt) (Xen Hypervisor Information Leaks Vulnerabilities (XSA 121 & 122))
|
|
|
|
- [Qubes Security Bulletin \#17](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-017-2015.txt) (Xen DoS from malicious driver domains or devices (XSA 120 & 124))
|
|
|
|
- [Qubes Security Bulletin \#18](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-018-2015.txt) (Xen Hypervisor Instruction Emulation Bug (XSA 123))
|
|
|
|
- [Qubes Security Bulletin \#19](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-019-2015.txt) (Anti Evil Maid bypass through unusual LUKS header)
|
|
|
|
- [Qubes Security Bulletin \#20](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-020-2015.txt) (Fedora os-prober considered harmful)
|
|
|
|
- [Qubes Security Bulletin \#21](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-021-2015.txt) (Anti Evil Maid bypass through filesystem ID collision)
|
|
|
|
- [Qubes Security Bulletin \#22](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-022-2015.txt) (Critical Xen bug in PV memory virtualization code (XSA 148))
|
2016-01-04 23:18:05 -05:00
|
|
|
- [Qubes Security Bulletin \#23](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-023-2015.txt) (Race condition bugs in Xen code (XSA-155 and XSA-166), other Xen bugs)
|
2014-01-09 12:19:34 -05:00
|
|
|
|
2016-07-27 16:49:58 -04:00
|
|
|
2016
|
|
|
|
----
|
|
|
|
|
|
|
|
- [Qubes Security Bulletin \#24](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt) (Critical Xen bug in PV memory virtualization code (XSA 182))
|
2016-09-17 17:00:55 -04:00
|
|
|
- [Qubes Security Bulletin \#25](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-025-2016.txt) (Xen bug in event channel handling code (XSA 188))
|
2016-09-21 13:56:55 -04:00
|
|
|
- [Qubes Security Bulletin \#26](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-026-2016.txt) (Colored window border handling bug in Qubes GUI daemon)
|
2016-11-22 09:00:21 -05:00
|
|
|
- [Qubes Security Bulletin \#27](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-027-2016.txt) (Xen 64-bit bit test instruction emulation broken (XSA 195))
|
2016-12-20 06:04:53 -05:00
|
|
|
- [Qubes Security Bulletin \#28](https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-028-2016.txt) (Debian update mechanism vulnerability)
|
2016-07-27 16:49:58 -04:00
|
|
|
|