TGViewer
Qubes OS Qubes OS @qubesos · 1.38K subscribers
Post #1209 164
XSAs released on 2026-09-08
https://www.qubes-os.org/news/2026/09/08/xsas-released-on-2026-09-08/

The Xen Project (https://xenproject.org/) has released one or more Xen security advisories (XSAs) (https://xenbits.xen.org/xsa/).
The security of Qubes OS is not affected.

XSAs that DO affect the security of Qubes OS

The following XSAs do affect the security of Qubes OS:


(none)


XSAs that DO NOT affect the security of Qubes OS

The following XSAs do not affect the security of Qubes OS, and no user action is necessary:


XSA-509 (https://xenbits.xen.org/xsa/advisory-509.html): Denial of service only.
XSA-510 (https://xenbits.xen.org/xsa/advisory-510.html): Denial of service only.
XSA-511 (https://xenbits.xen.org/xsa/advisory-511.html): Qubes OS does not use XSM silo.
XSA-512 (https://xenbits.xen.org/xsa/advisory-512.html): Qubes OS does not use oxenstored.
XSA-513 (https://xenbits.xen.org/xsa/advisory-513.html): Qubes OS does not use tapdisk.


About this announcement

Qubes OS uses the Xen hypervisor (https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview) as part of its architecture (https://doc.qubes-os.org/en/latest/developer/system/architecture.html). When the Xen Project (https://xenproject.org/) publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA) (https://xenproject.org/developers/security-policy/). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker (https://www.qubes-os.org/security/xsa/), which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.
More from @qubesos
  1. Sep 27, 2026NovaCustom builds custom laptops, mini PCs, and smartphones with a focus on privacy, secur…
  2. Sep 27, 2026photo post
  3. Sep 27, 2026The FPF is a long-standing Qubes Partner (https://www.qubes-os.org/partners/). As a nonpro…
  4. Sep 27, 2026Qubes OS Summit 2026: Freedom of the Press Foundation and NovaCustom sponsorships; confere…
  5. Sep 19, 2026View the full list of known bugs affecting Qubes 4.3 (https://github.com/QubesOS/qubes-iss…
  6. Sep 19, 2026Qubes OS 4.3.2-rc1 is available for testing https://www.qubes-os.org/news/2026/09/18/qubes…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →