Qubes OS 4.3.2 ships with two code-execution fixes folded in
The stable patch build lands just as the 4.2 series slides into end of life.
Qubes OS 4.3.2 is out today, and it's a patch release that folds in every security fix and bug correction shipped since 4.3.1. Existing 4.3 users can update in place. New installers get a clean ISO.
The real reason to upgrade is security. This window hides two bulletins that both cover code-execution flaws, and both let an attacker seize control of either a qube or dom0 itself.
What actually changed
On top of the security work, 4.3.2 delivers two version bumps you'll spot right away.
The default Fedora template climbs to Fedora 44, so TemplateVM tracks one of the freshest Fedora releases straight out of the box. The kernel-latest rolling kernel jumps to Linux 7.2 for anyone who opts in.
The bug-fix window runs from June 11, 2026, the day 4.3.1 landed, through September 18, 2026, when the release candidate went public. It covers a spread of closed reports filed against 4.3.
Head here for the full 4.3 release notes if you want the bigger picture.
Two bulletins, both bad
The first is QSB-119. It lives in the qvm-open-in-vm helper, the tool you use to open a file inside another qube. A format string an attacker could control might let code run inside the target qube, but the setup is fussy.
The filename has to clear 248 bytes, or the target directory needs to be non-writable. You also want printf-style specifiers like %n hiding in the path. And the Debian packages had to ship without _FORTIFY_SOURCE hardening, which came from a clash between Qubes' build script and how Debian handles that flag. Fedora packages were never affected.
That said, only Debian templates sit in the crosshairs. Reporters tested exploitability and found it succeeded under 3% of the time under contrived conditions, yet the project still issued the bulletin because qvm-open-in-vm exists precisely to handle untrusted input. The fix is qubes-core-agent 4.3.48.
The second bulletin, QSB-118, is the uglier of the pair. Copy a file from dom0 into a malicious qube and that qube can inject a command back into dom0. Flawed error reporting is to blame here: sanitize_remote_filename() strips non-ASCII characters and double quotes but leaves shell metacharacters in place, and the error dialog then runs through system(). The VM-side variant dodged the problem by using execlp instead. Fix is qubes-core-dom0-linux 4.3.22.
Both bulletins recommend simply updating as part of the normal patch cycle. No special steps required.
How to get it
If you're still on Qubes 4.2, upgrade now. That series reached end of life on June 21, 2026, so it no longer receives security updates or bug fixes. Three paths exist overall.
First-time installers grab the 4.3.2 ISO from the downloads page, complete with signature files. People already on 4.3 (including 4.3.0, 4.3.1, and 4.3.2-rc1) run the Qubes Update tool, which also pushes any end-of-life templates and standalones to current versions. No reinstall needed.
Keep in mind that the project strongly suggests a full backup before touching any of this.
There's one documented known issue. Templates restored from a pre-4.3 backup may still point at their original release repositories, per issue #8701. If that applies, run these commands in dom0 to point them at the 4.3 repos. The templates get shut down during the process.
sudo qubes-dom0-update -y qubes-dist-upgrade sudo qubes-dist-upgrade --releasever=4.3 --template-standalone-upgrade -y
Clean installs and in-place 4.2-to-4.3 upgrades already carry the fix, so you can skip the dance.
Head here for the release announcement.
