87 out of 109 Qubes security bulletins across all the years aren't about bugs in Qubes itself, but about Xen, CPU microarchitecture, and other upstream stuff. That's the conclusion of a longitudinal analysis of 109 QSBs from 2011 to 2025: nearly 80% of the issues come from components that the Qubes team doesn't write, but is merely forced to isolate.
And that, by the way, is the whole essence of their architecture — the boundaries between VMs are built so that a hole in Xen becomes a hole in the entire security model. The author also dug into the trends: the main turning point in advisory frequency happened in 2015Q1, and after 2018 the disclosure flow plateaued and has been statistically holding steady. S-shaped vulnerability prediction models over a short horizon, by the way, didn't beat a plain old moving average in any way.
A good example of how solid isolation doesn't remove the dependency on someone else's code — it just honestly reveals it in a public log.
Post #158
26