<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Qubes OS Research on iasds</title><link>https://iasds.github.io/qubes/</link><description>Recent content in Qubes OS Research on iasds</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 29 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://iasds.github.io/qubes/index.xml" rel="self" type="application/rss+xml"/><item><title>QSB-116: Xen Vulnerabilities (XSA-500/505/506/507) — Research PoCs</title><link>https://iasds.github.io/qubes/qsb-116-xen-vulnerabilities-poc/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><guid>https://iasds.github.io/qubes/qsb-116-xen-vulnerabilities-poc/</guid><description>&lt;p&gt;On 2026-07-28, the Qubes Security Team published &lt;a href="https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt"&gt;QSB-116&lt;/a&gt;, covering four Xen vulnerabilities disclosed the same day:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;XSA&lt;/th&gt;
					&lt;th&gt;CVE&lt;/th&gt;
					&lt;th&gt;Title&lt;/th&gt;
					&lt;th&gt;Xen Versions Affected&lt;/th&gt;
					&lt;th&gt;Default Qubes Config&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;XSA-500&lt;/td&gt;
					&lt;td&gt;CVE-2026-62428&lt;/td&gt;
					&lt;td&gt;grant-table: type confusion in grant-copy&lt;/td&gt;
					&lt;td&gt;≥ 4.2&lt;/td&gt;
					&lt;td&gt;Affected&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;XSA-505&lt;/td&gt;
					&lt;td&gt;CVE-2026-62432&lt;/td&gt;
					&lt;td&gt;evtchn: Race between FIFO expand and reset&lt;/td&gt;
					&lt;td&gt;≥ 4.5&lt;/td&gt;
					&lt;td&gt;Stubdomains only (QEMU needed first)&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;XSA-506&lt;/td&gt;
					&lt;td&gt;CVE-2026-62433&lt;/td&gt;
					&lt;td&gt;correct buffer checks for DM_OP hypercalls&lt;/td&gt;
					&lt;td&gt;≥ 4.10&lt;/td&gt;
					&lt;td&gt;Untrusted HVM qubes&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;XSA-507&lt;/td&gt;
					&lt;td&gt;CVE-2026-62434&lt;/td&gt;
					&lt;td&gt;PoD: Don&amp;rsquo;t try to reclaim special pages&lt;/td&gt;
					&lt;td&gt;≥ 3.4&lt;/td&gt;
					&lt;td&gt;Affected with relevant memory-balancing configuration&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;These are research PoCs using &lt;code&gt;privcmd&lt;/code&gt; ioctls and Xen headers, without a &lt;code&gt;libxenctrl&lt;/code&gt; dependency. A successful build or a timeout is not evidence that a vulnerability was triggered; record the Xen version, guest configuration, return code, and Xen log for every run.&lt;/p&gt;</description></item><item><title>Build Security Doesn't Need Full Determinism — A Practical Multi-Sig + Transparency Log Approach</title><link>https://iasds.github.io/qubes/build-security-multi-sig/</link><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><guid>https://iasds.github.io/qubes/build-security-multi-sig/</guid><description>&lt;p&gt;Qubes&amp;rsquo; current release signing flow relies on a single point of trust — one person holds the release key. It&amp;rsquo;s worked for over a decade, but &amp;ldquo;hasn&amp;rsquo;t been compromised yet&amp;rdquo; isn&amp;rsquo;t the same as &amp;ldquo;can&amp;rsquo;t be compromised.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Everyone agrees deterministic builds + multi-signature is the right direction. Issue #816 has been open for years, which shows the community knows its value. But full determinism is a heavy lift — getting thousands of packages across dozens of upstream projects to produce bit-identical output is a massive undertaking.&lt;/p&gt;</description></item><item><title>Clash Gateway — Transparent Proxy Guide</title><link>https://iasds.github.io/qubes/clash-gateway-guide/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://iasds.github.io/qubes/clash-gateway-guide/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;This guide explains how to set up a transparent proxy gateway on Qubes OS using &lt;a href="https://github.com/iasds/qubes-clash-gateway"&gt;qubes-clash-gateway&lt;/a&gt;, powered by &lt;a href="https://github.com/MetaCubeX/mihomo"&gt;mihomo&lt;/a&gt; (formerly Clash Meta).&lt;/p&gt;
&lt;p&gt;Unlike per-AppVM proxy configurations, this approach turns a single NetVM into a proxy gateway. All downstream AppVMs get proxied automatically with &lt;strong&gt;zero configuration&lt;/strong&gt; — just set the NetVM and go.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Transparent proxy for all TCP/UDP traffic&lt;/li&gt;
&lt;li&gt;DNS fake-ip to prevent DNS pollution&lt;/li&gt;
&lt;li&gt;GeoIP rule-based routing (CN direct, foreign proxy)&lt;/li&gt;
&lt;li&gt;Subscription parser supporting Clash YAML, vmess/vless/ss/ssr/trojan/hy2/tuic/wireguard&lt;/li&gt;
&lt;li&gt;Terminal controller &lt;code&gt;clashctl&lt;/code&gt; + Web UI for management&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;How it works:&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>