<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Qubes OS</title>
    <description>Qubes is a security-oriented, free and open-source operating system for personal computers that allows you to securely compartmentalize your digital life.
</description>
    <link>https://www.qubes-os.org/</link>
    <atom:link href="https://www.qubes-os.org/feed.xml" rel="self" type="application/rss+xml"/>
    <pubDate>Tue, 28 Jul 2026 16:25:30 +0000</pubDate>
    <lastBuildDate>Tue, 28 Jul 2026 16:25:30 +0000</lastBuildDate>
    <generator>Jekyll v3.10.0</generator>
    
      <item>
        <title>XSAs released on 2026-07-28</title>
        <description>&lt;p&gt;The &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; has released one or more &lt;a href=&quot;https://xenbits.xen.org/xsa/&quot;&gt;Xen security advisories (XSAs)&lt;/a&gt;.
The security of Qubes OS &lt;strong&gt;is affected&lt;/strong&gt;.&lt;/p&gt;

&lt;h2 id=&quot;xsas-that-do-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do affect&lt;/strong&gt; the security of Qubes OS:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-500.html&quot;&gt;XSA-500&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-505.html&quot;&gt;XSA-505&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-506.html&quot;&gt;XSA-506&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-507.html&quot;&gt;XSA-507&lt;/a&gt;: See &lt;a href=&quot;https://www.qubes-os.org/news/2026/07/28/qsb-116/&quot;&gt;QSB-116&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;xsas-that-do-not-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO NOT affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do not affect&lt;/strong&gt; the security of Qubes OS, and no user action is necessary:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-495.html&quot;&gt;XSA-495&lt;/a&gt;: Denial of service only. Shadow paging is disabled in Qubes OS at build time.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-496.html&quot;&gt;XSA-496&lt;/a&gt;: Denial of service only. Affects only Xen 4.21 and higher; Qubes OS 4.3 uses Xen 4.19.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-497.html&quot;&gt;XSA-497&lt;/a&gt;: Qubes OS does not use pygrub.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-499.html&quot;&gt;XSA-499&lt;/a&gt;: Denial of service only.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-501.html&quot;&gt;XSA-501&lt;/a&gt;: Qubes OS has grant tables v2 disabled.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-502.html&quot;&gt;XSA-502&lt;/a&gt;: Qubes OS does not use vnuma.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-503.html&quot;&gt;XSA-503&lt;/a&gt;: Allows leaking internal information about a qube only to itself, not other qubes.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-504.html&quot;&gt;XSA-504&lt;/a&gt;: Viridian is not enabled in Qubes OS.&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-508.html&quot;&gt;XSA-508&lt;/a&gt;: Qubes OS does not use pygrub.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;about-this-announcement&quot;&gt;About this announcement&lt;/h2&gt;

&lt;p&gt;Qubes OS uses the &lt;a href=&quot;https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview&quot;&gt;Xen hypervisor&lt;/a&gt; as part of its &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/system/architecture.html&quot;&gt;architecture&lt;/a&gt;. When the &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a &lt;a href=&quot;https://xenproject.org/developers/security-policy/&quot;&gt;Xen security advisory (XSA)&lt;/a&gt;. Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt;. (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only &lt;em&gt;positive&lt;/em&gt; confirmation that certain XSAs &lt;em&gt;do&lt;/em&gt; affect the security of Qubes OS. QSBs cannot provide &lt;em&gt;negative&lt;/em&gt; confirmation that other XSAs do &lt;em&gt;not&lt;/em&gt; affect the security of Qubes OS. Therefore, we also maintain an &lt;a href=&quot;https://www.qubes-os.org/security/xsa/&quot;&gt;XSA tracker&lt;/a&gt;, which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.&lt;/p&gt;
</description>
        <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/28/xsas-released-on-2026-07-28/</guid>
        
        
        <category>security</category>
        
      </item>
    
      <item>
        <title>QSB-116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)</title>
        <description>&lt;p&gt;We have published &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt&quot;&gt;Qubes Security Bulletin (QSB) 116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)&lt;/a&gt;. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.&lt;/p&gt;

&lt;h2 id=&quot;qubes-security-bulletin-116&quot;&gt;Qubes Security Bulletin 116&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;
             ---===[ Qubes Security Bulletin 116 ]===---

                              2026-07-28

       Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the &quot;Patching&quot; section below. No other user action is
required in response to this QSB.

Summary
--------

On 2026-07-28, the Xen Project published the security advisories below.

XSA-500 [3] &quot;grant-table: type confusion in grant-copy&quot;:

| When grant-copy operations are processed, the respective grant may or
| may not already be in use by another operation (a mapping or another
| copy). For all copy operations the referenced guest frame is looked
| up. When another operation is already active for the grant (the grant
| is &quot;pinned&quot;), what is being supplied back to actually carry out
| permission checks and copy operation may not be consistent: The
| permission check may be carried out on a page different from the one
| involved in the copy.


XSA-505 [4] &quot;evtchn: Race between FIFO expand and reset&quot;:

| The EVTCHNOP_expand_array hypercall checks for whether FIFO event
| channels are enabled, but without holding the correct lock. It can
| race with EVTCHNOP_reset, resulting in deferencing a NULL pointer.


XSA-506 [5] &quot;correct buffer checks for DM_OP hypercalls&quot;:

| Parts of the DM_OP handling code assumes the caller has provided the
| required number of buffers for the given operation without any
| checking being done. As a result, certain operations might access
| stack rubble as structures are possibly uninitialized.

XSA-507 [6] &quot;PoD: Don&apos;t try to reclaim special pages&quot;:

| A guest started with Populated on Demand enabled (PoD) can attempt to
| reclaim pages which aren&apos;t regular guest RAM. This can cause
| corruption of memory management state in Xen.

Impact
-------

XSA-500 and XSA-507: A malicious qube may be able to compromise
Qubes OS.

XSA-505: A malicious PV qube [7] may be able to compromise Qubes OS. The
same impact applies to stubdomains for HVM qubes [8], but in this case
an attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

XSA-506: The stubdomain for an HVM qube may be able to leak data from
other qubes in the system. In order to exploit this vulnerability, an
attacker would first have to discover and exploit an independent
vulnerability (in QEMU) in order to gain access to the stubdomain.

Affected systems
-----------------

XSA-500: All systems are affected.

XSA-505: Systems with either PV qubes or stubdomains for HVM qubes (or
both) are affected, but the vulnerability is easier to exploit on
systems with PV qubes. In the default Qubes OS configuration, there are
no PV qubes, but sys-net and sys-usb are HVM qubes that have
stubdomains. This means that the vulnerability is more difficult to
exploit in the default Qubes OS configuration, but if a user has
manually created PV qubes in a particular system, the vulnerability will
be easier to exploit on that system.

XSA-506: Systems with untrusted HVM qubes are affected. In the default
configuration of Qubes OS, sys-net and sys-usb are HVM qubes and are
considered to be untrusted.

XSA-507: Systems are affected if they have qubes that are included in
memory balancing but that don&apos;t advertise memory hotplug support. This
includes malicious HVM qubes with memory balancing enabled, as well as
templates and standalones that use in-qube kernels and that have memory
balancing enabled. The default Qubes OS configuration is not affected,
nor are commonly-used HVM qubes like Windows, since they don&apos;t have
memory balancing enabled.

Patching
---------

The following packages contain security updates that address the
vulnerabilities described in this bulletin:

  For Qubes 4.3, in dom0:
  - Xen packages, version 4.19.5-2

These packages will migrate from the security-testing repository to the
current (stable) repository over the next two weeks after being tested
by the community. [2] Once available, the packages should be installed
via the Qubes Update tool or its command-line equivalents. [1]

Dom0 must be restarted afterward in order for the updates to take
effect.

If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new Xen
binaries.

Credits
--------

See the original Xen Security Advisories. [3][4][5][6]

References
-----------

[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://xenbits.xen.org/xsa/advisory-500.html
[4] https://xenbits.xen.org/xsa/advisory-505.html
[5] https://xenbits.xen.org/xsa/advisory-506.html
[6] https://xenbits.xen.org/xsa/advisory-507.html
[7] A PV qube is a qube that is running with virt_mode set to &quot;pv.&quot;
[8] For each qube that is running with virt_mode set to &quot;hvm,&quot; there&apos;s a
    small Xen-internal helper VM running alongside it, in which QEMU is
    executed to provide device emulation for that qube. This helper VM
    runs in PV mode and is called a &quot;stubdomain.&quot;

--
The Qubes Security Team
https://www.qubes-os.org/security/

&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt&quot;&gt;qsb-116-2026.txt&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;marek-marczykowski-góreckis-pgp-signature&quot;&gt;&lt;a href=&quot;https://www.qubes-os.org/team/#marek-marczykowski-górecki&quot;&gt;Marek Marczykowski-Górecki&lt;/a&gt;’s PGP signature&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmpoeyMACgkQ1lWk8hgw
4GqUjw//brO4x3oOygOpewPqcjgYqohh4qPu5Dpm6JBvtxiIZQWEv9UZg0RqfMVc
omoalUCQhoTPu8QYnXu3HKo87LGcrUKKf2KeRx4CyT8LsZCQufA25uWD3Sr6eVsA
38Q/Znq3VyUpa5tMQm28JIIA9m2PMAMaXu5ElZVAw5kvcRncwRh8WDOrkVOO97ll
gSfBo3SJ0OfSUDcQvGa8f5+4Jx/SPoJn5zLo3Ott4tT7Tz2NAfE2Xlxl7karasY/
vCY+Lo8ACN+0ShELslGKYZnNdwLuwkz3lVN+FqDbLrHauBUjDLH7+yTXJvO9ZoXq
3LTpHopzv8oSJJyhq0YeO4XlKt+USn2HbIMqhJ9ON8aHHVE3/YhVJume4RuxSlHx
WAStN0bYH/NqSywYB3wWmGEho9wRw8bxLrOBIuZO3V63HpMJnCL412F7RFA2/9iS
muq3Iix9YpqfI/Q1Q18JSnYYLlWaphMtc/OJki5FAzp1B5DtQtPcQtg/vcy9tsrX
P9zrK4j3Dj/vPzZd6DwDmTBPxuiLQX79TQojl7NClVatkULfdHQGDKogfPmsJng9
IpKMBkMZ85QVv+DG/XFtXpynBdeg/6eTeWiexC7WF3HgILkhy2RadQz0eHsEwCmp
fIeVYQ2Es3eVH7aNaPHwaAcklNP+7yppgw5O81PGOlbD3Z9a15Y=
=vPOZ
-----END PGP SIGNATURE-----
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt.sig.marmarek&quot;&gt;qsb-116-2026.txt.sig.marmarek&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;simon-gaiser-aka-hw42s-pgp-signature&quot;&gt;&lt;a href=&quot;https://www.qubes-os.org/team/#simon-gaiser-aka-hw42&quot;&gt;Simon Gaiser (aka HW42)&lt;/a&gt;’s PGP signature&lt;/h2&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmpoh00ACgkQSsGN4REu
FJCSVhAApAdVntLjACF7SJ9h7SF4M1IiDKKUQRnUhwEa06d/qDjFg/aVlsL6LghW
+cKpPdjSDWwGPhAsJhbxTeiSSAkX300qJuqX3/K0h6iw7jaQkqb6kmwaAhK7J8Ym
9F5LvcP8Vvx3G0Gi4YogNzrwA+AMlfCgKLgp7MsHKumE1TY0pp5dI6DMqz2/EasV
ODrppsfXkMMmES5aR8C6Pxe51pfBbXVqVmffjYxaz/C9VvcfGbHja8OdnOuNeqmo
yzR2pP6BGdIl2KGfq1GzuuYWtitIcrG8aEnYfcmhiHbHkTIObNwHo7MOwBT2Q9H4
ALJfuBfC1ChBvmmzRIPgOzPbiz0MLIWcjFvKRmXW8azTTQOyRQQbG5lDGeu+aJm0
ZRdyXPQh2294MmmL3r+xtyFJTFw5WABdxjZa10nlB5B5JQ8FrV7koNc4quXhCS4U
ceAwpvCuRKTX1Lg+NDaPFtxAmYX98QkLT09V34vyqksOcMR+DY7stHol8T+hYIMM
8DXZDBdndUMkU/DU5xfj4Z/wtgkB66eLKBypxqibiPx33vkBZOIAYtNYK7zFnrTk
HnrHAGpm0sLlNdLzNA4XQ7yMTdDwzxW6GeYacYWxDT3t9Qc9vroGVju3CExQtljs
4znS5FAHrlPSv4xi7aWiypVwB/MsMbrdNcd0/g9px6RbszpNGpA=
=BjeB
-----END PGP SIGNATURE-----
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://github.com/QubesOS/qubes-secpack/blob/f9001423ffb11de26bdcf0b4478838739cc3f6b3/QSBs/qsb-116-2026.txt.sig.simon&quot;&gt;qsb-116-2026.txt.sig.simon&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;what-is-the-purpose-of-this-announcement&quot;&gt;What is the purpose of this announcement?&lt;/h2&gt;

&lt;p&gt;The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.&lt;/p&gt;

&lt;h2 id=&quot;what-is-a-qubes-security-bulletin-qsb&quot;&gt;What is a Qubes security bulletin (QSB)?&lt;/h2&gt;

&lt;p&gt;A &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt; is a security announcement issued by the &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team&quot;&gt;Qubes security team&lt;/a&gt;. A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.&lt;/p&gt;

&lt;h2 id=&quot;why-should-i-care-about-qsbs&quot;&gt;Why should I care about QSBs?&lt;/h2&gt;

&lt;p&gt;QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html&quot;&gt;updating normally&lt;/a&gt;. However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.&lt;/p&gt;

&lt;h2 id=&quot;what-are-the-pgp-signatures-that-accompany-qsbs&quot;&gt;What are the PGP signatures that accompany QSBs?&lt;/h2&gt;

&lt;p&gt;A &lt;a href=&quot;https://en.wikipedia.org/wiki/Pretty_Good_Privacy&quot;&gt;PGP&lt;/a&gt; signature is a cryptographic &lt;a href=&quot;https://en.wikipedia.org/wiki/Digital_signature&quot;&gt;digital signature&lt;/a&gt; made in accordance with the &lt;a href=&quot;https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP&quot;&gt;OpenPGP&lt;/a&gt; standard. PGP signatures can be cryptographically verified with programs like &lt;a href=&quot;https://gnupg.org/&quot;&gt;GNU Privacy Guard (GPG)&lt;/a&gt;. The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.&lt;/p&gt;

&lt;h2 id=&quot;why-should-i-care-whether-a-qsb-is-authentic&quot;&gt;Why should I care whether a QSB is authentic?&lt;/h2&gt;

&lt;p&gt;A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.&lt;/p&gt;

&lt;h2 id=&quot;how-do-i-verify-the-pgp-signatures-on-a-qsb&quot;&gt;How do I verify the PGP signatures on a QSB?&lt;/h2&gt;

&lt;p&gt;The following command-line instructions assume a Linux system with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;git&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg&lt;/code&gt; installed. (For Windows and Mac options, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software&quot;&gt;OpenPGP software&lt;/a&gt;.)&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;Obtain the Qubes Master Signing Key (QMSK), e.g.:&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--fetch-keys&lt;/span&gt; https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
&lt;span class=&quot;go&quot;&gt;gpg: directory &apos;/home/user/.gnupg&apos; created
gpg: keybox &apos;/home/user/.gnupg/pubring.kbx&apos; created
gpg: requesting key from &apos;https://keys.qubes-os.org/keys/qubes-master-signing-key.asc&apos;
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: key DDFA1A3E36879494: public key &quot;Qubes Master Signing Key&quot; imported
gpg: Total number processed: 1
gpg:               imported: 1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;(For more ways to obtain the QMSK, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key&quot;&gt;How to import and authenticate the Qubes Master Signing Key&lt;/a&gt;.)&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;View the fingerprint of the PGP key you just imported. (Note: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg&amp;gt;&lt;/code&gt; indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--edit-key&lt;/span&gt; 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
&lt;span class=&quot;gp&quot;&gt;gpg (GnuPG) 2.2.27;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;Copyright &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;C&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; 2021 Free Software Foundation, Inc.
&lt;span class=&quot;go&quot;&gt;This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
   
   
pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: unknown       validity: unknown
[ unknown] (1). Qubes Master Signing Key
   
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;fpr
&lt;span class=&quot;go&quot;&gt;pub   rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
 Primary key fingerprint: 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt; At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you &lt;em&gt;must&lt;/em&gt; authenticate the QMSK out-of-band. &lt;strong&gt;Do not skip this step!&lt;/strong&gt; The standard method is to obtain the QMSK fingerprint from &lt;em&gt;multiple independent sources in several different ways&lt;/em&gt; and check to see whether they match the key you just imported. For more information, see &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key&quot;&gt;How to import and authenticate the Qubes Master Signing Key&lt;/a&gt;.&lt;/p&gt;

    &lt;p&gt;&lt;strong&gt;Tip:&lt;/strong&gt; After you have authenticated the QMSK out-of-band to your satisfaction, record the QMSK fingerprint in a safe place (or several) so that you don’t have to repeat this step in the future.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Once you are satisfied that you have the genuine QMSK, set its trust level to 5 (“ultimate”), then quit GnuPG with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;q&lt;/code&gt;.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;trust
&lt;span class=&quot;go&quot;&gt;pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: unknown       validity: unknown
[ unknown] (1). Qubes Master Signing Key
   
Please decide how far you trust this user to correctly verify other users&apos; keys
(by looking at passports, checking fingerprints from different sources, etc.)
   
  1 = I don&apos;t know or won&apos;t say
  2 = I do NOT trust
  3 = I trust marginally
  4 = I trust fully
  5 = I trust ultimately
  m = back to the main menu
   
Your decision? 5
Do you really want to set this key to ultimate trust? (y/N) y
   
pub  rsa4096/DDFA1A3E36879494
     created: 2010-04-01  expires: never       usage: SC
     trust: ultimate      validity: unknown
[ unknown] (1). Qubes Master Signing Key
Please note that the shown key validity is not necessarily correct
unless you restart the program.
   
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;gpg&amp;gt;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;q
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Use Git to clone the qubes-secpack repo.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;git clone https://github.com/QubesOS/qubes-secpack.git
&lt;span class=&quot;go&quot;&gt;Cloning into &apos;qubes-secpack&apos;...
remote: Enumerating objects: 4065, done.
remote: Counting objects: 100% (1474/1474), done.
remote: Compressing objects: 100% (742/742), done.
remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591
Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done.
Resolving deltas: 100% (1910/1910), done.
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Import the included PGP keys. (See our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/security-pack.html#pgp-key-policies&quot;&gt;PGP key policies&lt;/a&gt; for important information about these keys.)&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--import&lt;/span&gt; qubes-secpack/keys/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;
&lt;span class=&quot;go&quot;&gt;gpg: key 063938BA42CFA724: public key &quot;Marek Marczykowski-Górecki (Qubes OS signing key)&quot; imported
gpg: qubes-secpack/keys/core-devs/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key 8C05216CE09C093C: 1 signature not checked due to a missing key
gpg: key 8C05216CE09C093C: public key &quot;HW42 (Qubes Signing Key)&quot; imported
gpg: key DA0434BC706E1FCF: public key &quot;Simon Gaiser (Qubes OS signing key)&quot; imported
gpg: key 8CE137352A019A17: 2 signatures not checked due to missing keys
gpg: key 8CE137352A019A17: public key &quot;Andrew David Wong (Qubes Documentation Signing Key)&quot; imported
gpg: key AAA743B42FBC07A9: public key &quot;Brennan Novak (Qubes Website &amp;amp; Documentation Signing)&quot; imported
gpg: key B6A0BB95CA74A5C3: public key &quot;Joanna Rutkowska (Qubes Documentation Signing Key)&quot; imported
gpg: key F32894BE9684938A: public key &quot;Marek Marczykowski-Górecki (Qubes Documentation Signing Key)&quot; imported
gpg: key 6E7A27B909DAFB92: public key &quot;Hakisho Nukama (Qubes Documentation Signing Key)&quot; imported
gpg: key 485C7504F27D0A72: 1 signature not checked due to a missing key
gpg: key 485C7504F27D0A72: public key &quot;Sven Semmler (Qubes Documentation Signing Key)&quot; imported
gpg: key BB52274595B71262: public key &quot;unman (Qubes Documentation Signing Key)&quot; imported
gpg: key DC2F3678D272F2A8: 1 signature not checked due to a missing key
gpg: key DC2F3678D272F2A8: public key &quot;Wojtek Porczyk (Qubes OS documentation signing key)&quot; imported
gpg: key FD64F4F9E9720C4D: 1 signature not checked due to a missing key
gpg: key FD64F4F9E9720C4D: public key &quot;Zrubi (Qubes Documentation Signing Key)&quot; imported
gpg: key DDFA1A3E36879494: &quot;Qubes Master Signing Key&quot; not changed
gpg: key 1848792F9E2795E9: public key &quot;Qubes OS Release 4 Signing Key&quot; imported
gpg: qubes-secpack/keys/release-keys/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key D655A4F21830E06A: public key &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; imported
gpg: key ACC2602F3F48CB21: public key &quot;Qubes OS Security Team&quot; imported
gpg: qubes-secpack/keys/security-team/retired: read error: Is a directory
gpg: no valid OpenPGP data found.
gpg: key 4AC18DE1112E1490: public key &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; imported
gpg: Total number processed: 17
gpg:               imported: 16
gpg:              unchanged: 1
gpg: marginals needed: 3  completes needed: 1  trust model: pgp
gpg: depth: 0  valid:   1  signed:   6  trust: 0-, 0q, 0n, 0m, 0f, 1u
gpg: depth: 1  valid:   6  signed:   0  trust: 6-, 0q, 0n, 0m, 0f, 0u
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Verify signed Git tags.&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;qubes-secpack/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;git tag &lt;span class=&quot;nt&quot;&gt;-v&lt;/span&gt; &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;git describe&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;
&lt;span class=&quot;go&quot;&gt;object 266e14a6fae57c9a91362c9ac784d3a891f4d351
type commit
tag marmarek_sec_266e14a6
tagger Marek Marczykowski-Górecki 1677757924 +0100
   
Tag for commit 266e14a6fae57c9a91362c9ac784d3a891f4d351
gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;The exact output will differ, but the final line should always start with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg: Good signature from...&lt;/code&gt; followed by an appropriate key. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[full]&lt;/code&gt; indicates full trust, which this key inherits in virtue of being validly signed by the QMSK.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Verify PGP signatures, e.g.:&lt;/p&gt;

    &lt;div class=&quot;language-shell_session highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;QSBs/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; qsb-087-2022.txt.sig.simon qsb-087-2022.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST
gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
gpg: Good signature from &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd&lt;/span&gt; ../canaries/
&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; canary-034-2023.txt.sig.marmarek canary-034-2023.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST
gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
gpg: Good signature from &quot;Marek Marczykowski-Górecki (Qubes security pack)&quot; [full]
&lt;/span&gt;&lt;span class=&quot;gp&quot;&gt;$&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;gpg &lt;span class=&quot;nt&quot;&gt;--verify&lt;/span&gt; canary-034-2023.txt.sig.simon canary-034-2023.txt
&lt;span class=&quot;go&quot;&gt;gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST
gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
gpg: Good signature from &quot;Simon Gaiser (Qubes Security Pack signing key)&quot; [full]
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;

    &lt;p&gt;Again, the exact output will differ, but the final line of output from each &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg --verify&lt;/code&gt; command should always start with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpg: Good signature from...&lt;/code&gt; followed by an appropriate key.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For this announcement (QSB-116), the commands are:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;$ gpg --verify qsb-116-2026.txt.sig.marmarek qsb-116-2026.txt
$ gpg --verify qsb-116-2026.txt.sig.simon qsb-116-2026.txt
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You can also verify the signatures directly from this announcement in addition to or instead of verifying the files from the qubes-secpack. Simply copy and paste the QSB-116 text into a plain text file and do the same for both signature files. Then, perform the same authentication steps as listed above, substituting the filenames above with the names of the files you just created.&lt;/p&gt;
</description>
        <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/28/qsb-116/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/28/qsb-116/</guid>
        
        
        <category>security</category>
        
      </item>
    
      <item>
        <title>Qubes OS Summit 2026: Tickets for sale and speaker proposals now open!</title>
        <description>&lt;p&gt;&lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;Qubes OS Summit 2026&lt;/a&gt; is a three-day gathering of security enthusiasts, open-source developers, and digital privacy experts.&lt;/p&gt;

&lt;h2 id=&quot;when-and-where&quot;&gt;When and where&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Friday, October 30 @ 9:30 AM — Sunday, November 1 @ 3:00 PM (GMT+1)&lt;/strong&gt;&lt;br /&gt;
(A more specific schedule will be published after the speaker lineup is finalized.)&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://refugio.berlin/&quot;&gt;Refugio Berlin&lt;/a&gt;&lt;br /&gt;
Lenaustraße 3-4&lt;br /&gt;
12047 Berlin&lt;br /&gt;
&lt;a href=&quot;https://www.openstreetmap.org/way/263350430&quot;&gt;View on OpenStreetMap&lt;/a&gt;&lt;/p&gt;

&lt;h2 id=&quot;attend-in-person-or-online&quot;&gt;Attend in person or online&lt;/h2&gt;

&lt;p&gt;There are three ways to attend the Summit:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;strong&gt;In person at &lt;a href=&quot;https://refugio.berlin/&quot;&gt;Refugio Berlin&lt;/a&gt;&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Requires a &lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;paid on-site ticket&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;Grants access to the hackathon (including interactive workshops) and any design sessions (depending on conference schedule)&lt;/li&gt;
      &lt;li&gt;Provides the opportunity to socialize, network, and mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Grants exclusive access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Grants access to attend presentations and participate as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Actively participate online&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Requires a &lt;a href=&quot;https://pretix.eu/qubes/summit2026/&quot;&gt;free virtual ticket&lt;/a&gt;&lt;/li&gt;
      &lt;li&gt;For those who are presenting remotely&lt;/li&gt;
      &lt;li&gt;For those who are attending presentations remotely and wish to ask questions or engage in active discussion in a live chat during the presentations&lt;/li&gt;
      &lt;li&gt;Does not grant access to the hackathon or any design sessions&lt;/li&gt;
      &lt;li&gt;Does not provide the opportunity to socialize, network, or mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Does not grant access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Does not grant access to attend presentations as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Passively view online&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;No ticket or registration required&lt;/li&gt;
      &lt;li&gt;For those who simply wish to watch the presentations via the public livestream and recorded videos&lt;/li&gt;
      &lt;li&gt;Does not provide the ability to ask questions or engage in active discussion during the presentations&lt;/li&gt;
      &lt;li&gt;Does not grant access to the hackathon or any design sessions&lt;/li&gt;
      &lt;li&gt;Does not provide the opportunity to socialize, network, or mingle with like-minded individuals who are passionate about secure computing&lt;/li&gt;
      &lt;li&gt;Does not grant access to any non-livestreamed, non-recorded presentations (see below)&lt;/li&gt;
      &lt;li&gt;Does not grant access to attend presentations as a live audience member&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Presenters have the option to request that their presentations not be recorded. If a presenter opts out of recording, there will be a “no recording” icon next to that presentation in the conference schedule. Only on-site attendees will be able to view that presentation. It will not be livestreamed or recorded for later viewing.&lt;/p&gt;

&lt;h2 id=&quot;become-a-presenter&quot;&gt;Become a presenter&lt;/h2&gt;

&lt;p&gt;If you’d like to present at the Summit, please &lt;a href=&quot;https://pretalx.com/qubes-os-summit-2026/cfp&quot;&gt;submit your proposal&lt;/a&gt; by 2026-08-31.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;You may present either on site or virtually from anywhere in the world.&lt;/li&gt;
  &lt;li&gt;If your proposal is accepted and you wish to present in person, you’ll be issued an on-site ticket free of charge, no purchase necessary.&lt;/li&gt;
  &lt;li&gt;If you select “Don’t record this session” when submitting your proposal, your presentation will not be livestreamed or recorded. Online attendees will not be able to view it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;conference-schedule&quot;&gt;Conference schedule&lt;/h2&gt;

&lt;p&gt;We’re still reviewing proposals from prospective presenters, so the list of talks has not been decided yet. We’ll publish a detailed conference schedule after the speaker lineup has been finalized.&lt;/p&gt;

&lt;h2 id=&quot;become-a-sponsor&quot;&gt;Become a sponsor&lt;/h2&gt;

&lt;p&gt;If you or your organization are interested in sponsoring Qubes OS Summit 2026 or becoming a &lt;a href=&quot;https://www.qubes-os.org/partners/&quot;&gt;Qubes Partner&lt;/a&gt;, please contact us at &lt;a href=&quot;mailto:funding@qubes-os.org&quot;&gt;funding@qubes-os.org&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;code-of-conduct&quot;&gt;Code of conduct&lt;/h2&gt;

&lt;p&gt;This event is covered by the Qubes OS Project’s &lt;a href=&quot;https://doc.qubes-os.org/en/latest/introduction/code-of-conduct.html&quot;&gt;code of conduct&lt;/a&gt;.&lt;/p&gt;
</description>
        <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/23/qubes-os-summit-2026-tickets-for-sale-and-speaker-proposals-now-open/</guid>
        
        
        <category>announcements</category>
        
      </item>
    
      <item>
        <title>Fedora 44 templates available</title>
        <description>&lt;p&gt;The following new &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora.html&quot;&gt;Fedora 44 templates&lt;/a&gt; are now available for Qubes OS 4.3:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-xfce&lt;/code&gt; — default Fedora template with the &lt;a href=&quot;https://xfce.org/&quot;&gt;Xfce&lt;/a&gt; desktop environment&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-gnome&lt;/code&gt; — alternative Fedora template with the &lt;a href=&quot;https://www.gnome.org/&quot;&gt;GNOME&lt;/a&gt; desktop environment&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fedora-44-minimal&lt;/code&gt; — &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/minimal-templates.html&quot;&gt;minimal template&lt;/a&gt; for advanced users&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There are two ways to upgrade a template to a new Fedora release:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Recommended:&lt;/strong&gt; &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora.html#installing&quot;&gt;Install a fresh template to replace an existing one.&lt;/a&gt; This option is simpler for less experienced users, but it won’t preserve any modifications you’ve made to your template. After you install the new template, you’ll have to redo your desired template modifications (if any) and &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/templates.html#switching&quot;&gt;switch everything that was set to the old template to the new template&lt;/a&gt;. If you choose to modify your template, you may wish to write those modifications down so that you remember what to redo on each fresh install. To see a log of package manager actions, open a terminal in the template and use the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dnf history&lt;/code&gt; command.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Advanced:&lt;/strong&gt; &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/templates/fedora/fedora-upgrade.html&quot;&gt;Perform an in-place upgrade of an existing Fedora template.&lt;/a&gt; This option will preserve any modifications you’ve made to the template, but it may be more complicated for less experienced users.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; No user action is required regarding the OS version in dom0 (see our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html#note-on-dom0-and-eol&quot;&gt;note on dom0 and EOL&lt;/a&gt;).&lt;/p&gt;
</description>
        <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/23/fedora-44-templates-available/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/23/fedora-44-templates-available/</guid>
        
        
        <category>announcements</category>
        
      </item>
    
      <item>
        <title>XSAs released on 2026-07-14</title>
        <description>&lt;p&gt;The &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; has released one or more &lt;a href=&quot;https://xenbits.xen.org/xsa/&quot;&gt;Xen security advisories (XSAs)&lt;/a&gt;.
The security of Qubes OS is &lt;strong&gt;not&lt;/strong&gt; affected.&lt;/p&gt;

&lt;h2 id=&quot;xsas-that-do-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do affect&lt;/strong&gt; the security of Qubes OS:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;(none)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;xsas-that-do-not-affect-the-security-of-qubes-os&quot;&gt;XSAs that DO NOT affect the security of Qubes OS&lt;/h2&gt;

&lt;p&gt;The following XSAs &lt;strong&gt;do not affect&lt;/strong&gt; the security of Qubes OS, and no user action is necessary:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-498.html&quot;&gt;XSA-498&lt;/a&gt;: Qubes OS does not use XAPI.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;about-this-announcement&quot;&gt;About this announcement&lt;/h2&gt;

&lt;p&gt;Qubes OS uses the &lt;a href=&quot;https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview&quot;&gt;Xen hypervisor&lt;/a&gt; as part of its &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/system/architecture.html&quot;&gt;architecture&lt;/a&gt;. When the &lt;a href=&quot;https://xenproject.org/&quot;&gt;Xen Project&lt;/a&gt; publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a &lt;a href=&quot;https://xenproject.org/developers/security-policy/&quot;&gt;Xen security advisory (XSA)&lt;/a&gt;. Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a &lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Qubes security bulletin (QSB)&lt;/a&gt;. (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only &lt;em&gt;positive&lt;/em&gt; confirmation that certain XSAs &lt;em&gt;do&lt;/em&gt; affect the security of Qubes OS. QSBs cannot provide &lt;em&gt;negative&lt;/em&gt; confirmation that other XSAs do &lt;em&gt;not&lt;/em&gt; affect the security of Qubes OS. Therefore, we also maintain an &lt;a href=&quot;https://www.qubes-os.org/security/xsa/&quot;&gt;XSA tracker&lt;/a&gt;, which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.&lt;/p&gt;
</description>
        <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/14/xsas-released-on-2026-07-14/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/14/xsas-released-on-2026-07-14/</guid>
        
        
        <category>security</category>
        
      </item>
    
      <item>
        <title>Last chance to take the 2026 user survey! (10-20 minutes)</title>
        <description>&lt;p&gt;As &lt;a href=&quot;https://www.qubes-os.org/news/2026/06/29/reminder-take-the-2026-user-survey-to-help-shape-the-future-of-qubes/&quot;&gt;previously announced&lt;/a&gt;, Qubes OS User Survey 2026 will close on 2026-07-13. If you still wish to take the survey and haven’t completed it yet, please do so now.&lt;/p&gt;

&lt;p&gt;Whether you’re a long-time Qubes user or haven’t even installed it yet, we want to hear about your experiences and about what matters to you. Help us make Qubes the best reasonably secure operating system it can be. If you’ve ever wanted to influence the development of Qubes, now is your chance. Make your voice heard!&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://pad.itl.space/form/#/2/form/view/4+jrJP2pyim2EyFwrbXrOVbQpzUg71Kt+DWR6p2M3IU/&quot;&gt;Qubes OS User Survey 2026&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;This survey is fully anonymous. We do not collect any data except for the answers you provide.&lt;/em&gt;&lt;/p&gt;
</description>
        <pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/07/11/last-chance-to-take-the-2026-user-survey/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/07/11/last-chance-to-take-the-2026-user-survey/</guid>
        
        
        <category>announcements</category>
        
      </item>
    
      <item>
        <title>Reminder: Take the 2026 user survey to help shape the future of Qubes! (10-20 minutes)</title>
        <description>&lt;p&gt;As &lt;a href=&quot;https://www.qubes-os.org/news/2026/06/11/qubes-os-user-survey-2026/&quot;&gt;previously announced&lt;/a&gt;, Qubes OS User Survey 2026 is currently live! The survey will remain open for two more weeks, until 2026-07-13.&lt;/p&gt;

&lt;p&gt;Whether you’re a long-time Qubes user or haven’t even installed it yet, we want to hear about your experiences and about what matters to you. Help us make Qubes the best reasonably secure operating system it can be. If you’ve ever wanted to influence the development of Qubes, now is your chance. Make your voice heard!&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://pad.itl.space/form/#/2/form/view/4+jrJP2pyim2EyFwrbXrOVbQpzUg71Kt+DWR6p2M3IU/&quot;&gt;Qubes OS User Survey 2026&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;This survey is fully anonymous. We do not collect any data except for the answers you provide.&lt;/em&gt;&lt;/p&gt;
</description>
        <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/06/29/reminder-take-the-2026-user-survey-to-help-shape-the-future-of-qubes/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/06/29/reminder-take-the-2026-user-survey-to-help-shape-the-future-of-qubes/</guid>
        
        
        <category>announcements</category>
        
      </item>
    
      <item>
        <title>Qubes OS 4.2 has reached end of life</title>
        <description>&lt;p&gt;As &lt;a href=&quot;https://www.qubes-os.org/news/2026/04/27/qubes-os-4-2-approaching-end-of-life/&quot;&gt;previously announced&lt;/a&gt;, the Qubes OS 4.2 release series has officially reached end of life (EOL) as of today, 2026-06-21. We strongly urge all remaining Qubes 4.2 users to &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/upgrade/4_3.html&quot;&gt;upgrade to Qubes 4.3&lt;/a&gt; immediately.&lt;/p&gt;

&lt;h2 id=&quot;recommended-actions&quot;&gt;Recommended actions&lt;/h2&gt;

&lt;p&gt;If you’re already using Qubes 4.3, then you don’t have to do anything. This announcement doesn’t apply to you.&lt;/p&gt;

&lt;p&gt;If you’re still using Qubes 4.2, then you should upgrade to Qubes 4.3 as soon as possible. There are two ways to do this:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/upgrade/4_3.html#clean-installation-of-qubes-4-3&quot;&gt;Perform a clean installation of Qubes 4.3&lt;/a&gt; using the latest stable &lt;a href=&quot;https://www.qubes-os.org/news/2026/06/11/qubes-os-4-3-1-has-been-released/&quot;&gt;Qubes OS 4.3.1 ISO&lt;/a&gt;. This involves &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-back-up-restore-and-migrate.html&quot;&gt;backing up your current system&lt;/a&gt;, replacing your current installation with a &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/installation-guide.html&quot;&gt;fresh Qubes 4.3 installation&lt;/a&gt;, then &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-back-up-restore-and-migrate.html#restoring-from-a-backup&quot;&gt;restoring from your backup&lt;/a&gt;. Many users find this option to be simpler, easier, and less error-prone. However, if you’ve made extensive customizations in dom0, they may need to be redone.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/upgrade/4_3.html#in-place-upgrade-from-qubes-4-2-to-qubes-4-3&quot;&gt;Perform an in-place upgrade from Qubes 4.2 to Qubes 4.3.&lt;/a&gt; Instead of replacing your existing installation, this method involves installing a special command-line tool in dom0, then using it to upgrade your existing Qubes 4.2 installation to Qubes 4.3. This is a more complex multi-stage process, which makes it most suitable for advanced users. This method preserves your qubes and all the customizations you’ve made in dom0 that are compatible with the in-place upgrade process. While not strictly required, we still strongly recommend &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-back-up-restore-and-migrate.html&quot;&gt;making a full backup&lt;/a&gt; before attempting an in-place upgrade. This way, if anything goes wrong, your data is still safe, and you always have the option of falling back to performing a clean installation.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you need help, please consult our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/introduction/support.html&quot;&gt;help and support&lt;/a&gt; page.&lt;/p&gt;

&lt;h2 id=&quot;what-does-end-of-life-eol-mean&quot;&gt;What does end of life (EOL) mean?&lt;/h2&gt;

&lt;p&gt;When an operating system reaches end of life (EOL), it is no longer supported. This means that it will no longer receive security updates, bug fixes, or new features. An OS that does not receive security updates will not be protected against new vulnerabilities, which is why it’s critically important to upgrade to a supported release.&lt;/p&gt;

&lt;h2 id=&quot;what-about-patch-releases&quot;&gt;What about patch releases?&lt;/h2&gt;

&lt;p&gt;The Qubes OS Project uses the &lt;a href=&quot;https://semver.org/&quot;&gt;semantic versioning&lt;/a&gt; standard. Version numbers are written as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[major].[minor].[patch]&lt;/code&gt;. When a major or minor release reaches EOL, all of its patch releases also reach EOL. In this case, when we say that “Qubes 4.2” (without specifying a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[patch]&lt;/code&gt; number) has reached EOL, we’re specifying a particular minor release inclusive of all patch releases within it. This means that Qubes 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 4.2.4 have all reached EOL, since they’re all patch releases of the same minor release.&lt;/p&gt;

&lt;h2 id=&quot;how-are-eol-dates-determined&quot;&gt;How are EOL dates determined?&lt;/h2&gt;

&lt;p&gt;According to our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html&quot;&gt;release support policy&lt;/a&gt;, stable Qubes OS releases are supported for six months after each subsequent &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html&quot;&gt;major or minor release&lt;/a&gt;. This means that the EOL date for Qubes 4.2 was set at the time Qubes 4.3 was released by adding six months to the Qubes 4.3 release date. Qubes 4.3.0 was &lt;a href=&quot;https://www.qubes-os.org/news/2025/12/21/qubes-os-4-3-0-has-been-released/&quot;&gt;released on 2025-12-21&lt;/a&gt;. Adding six months to this date gives us 2026-06-21, which is Qubes 4.2’s EOL date. Since the EOL date of 4.2 was determined at the time 4.3 was released, we also &lt;a href=&quot;https://www.qubes-os.org/news/2025/12/21/qubes-os-4-3-0-has-been-released/#support-for-older-releases&quot;&gt;included this information in the 4.3.0 release announcement&lt;/a&gt;.&lt;/p&gt;
</description>
        <pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/06/21/qubes-os-4-2-has-reached-end-of-life/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/06/21/qubes-os-4-2-has-reached-end-of-life/</guid>
        
        
        <category>announcements</category>
        
        <category>releases</category>
        
      </item>
    
      <item>
        <title>Qubes OS User Survey 2026: Shape the future of Qubes! (10-20 minutes)</title>
        <description>&lt;p&gt;Whether you’re a long-time Qubes user or haven’t even installed it yet, we want to hear about your experiences and about what matters to you. Help us make Qubes the best reasonably secure operating system it can be. If you’ve ever wanted to influence the development of Qubes, now is your chance. Make your voice heard!&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://pad.itl.space/form/#/2/form/view/4+jrJP2pyim2EyFwrbXrOVbQpzUg71Kt+DWR6p2M3IU/&quot;&gt;Qubes OS User Survey 2026&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;This survey is fully anonymous. We do not collect any data except for the answers you provide.&lt;/em&gt;&lt;/p&gt;
</description>
        <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/06/11/qubes-os-user-survey-2026/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/06/11/qubes-os-user-survey-2026/</guid>
        
        
        <category>announcements</category>
        
      </item>
    
      <item>
        <title>Qubes OS 4.3.1 has been released!</title>
        <description>&lt;p&gt;We’re pleased to announce the stable release of Qubes OS 4.3.1! This patch release aims to consolidate all the security updates and bug fixes that have occurred since the previous stable release. Our goal is to provide a secure and convenient way for users to install (or reinstall) the latest stable Qubes release with an up-to-date ISO. The ISO and associated &lt;a href=&quot;https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html&quot;&gt;verification files&lt;/a&gt; are available on the &lt;a href=&quot;https://www.qubes-os.org/downloads/&quot;&gt;downloads&lt;/a&gt; page.&lt;/p&gt;

&lt;h2 id=&quot;announcements&quot;&gt;Announcements&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href=&quot;https://www.qubes-os.org/news/2026/04/27/qubes-os-4-2-approaching-end-of-life/&quot;&gt;Qubes 4.2 will reach end of life (EOL) on 2026-06-21&lt;/a&gt;. If you’re a current 4.2 user who’s been waiting to upgrade to 4.3, the release of Qubes 4.3.1 is the perfect opportunity to do so.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;a href=&quot;https://pad.itl.space/form/#/2/form/view/4+jrJP2pyim2EyFwrbXrOVbQpzUg71Kt+DWR6p2M3IU/&quot;&gt;Qubes OS User Survey 2026&lt;/a&gt; is now live! Whether you’re a long-time Qubes user or haven’t even installed it yet, we want to hear about your experiences and about what matters to you. Help us make Qubes the best reasonably secure operating system it can be. The survey takes 10-20 minutes and is fully anonymous. We do not collect any data except for the answers you provide. If you’ve ever wanted to influence the development of Qubes, now is your chance. Make your voice heard!&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;whats-new-in-qubes-431&quot;&gt;What’s new in Qubes 4.3.1?&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://www.qubes-os.org/security/qsb/&quot;&gt;Security updates&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20is%3Aclosed%20reason%3Acompleted%20type%3ABug%20label%3A%22affects-4.3%22%20closed%3A2025-12-21..2026-05-28%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22%20-label%3A%22C%3A%20website%22%20-label%3A%22C%3A%20infrastructure%22%20-label%3A%22C%3A%20tests%22&quot;&gt;Bug fixes&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;Included Fedora template upgraded to Fedora 43. (Reminder: &lt;a href=&quot;https://www.qubes-os.org/news/2026/03/13/fedora-42-approaching-end-of-life/&quot;&gt;Fedora 42 has reached end of life.&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you’re upgrading from Qubes 4.2, also see the &lt;a href=&quot;https://doc.qubes-os.org/en/r4.3/developer/releases/4_3/release-notes.html&quot;&gt;Qubes 4.3 release notes&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;how-to-get-qubes-431&quot;&gt;How to get Qubes 4.3.1&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;If you’d like to install Qubes for the first time or perform a clean reinstallation on an existing system, there’s never been a better time to do so! Simply &lt;a href=&quot;https://www.qubes-os.org/downloads/&quot;&gt;download&lt;/a&gt; the Qubes 4.3.1 ISO and follow our &lt;a href=&quot;https://doc.qubes-os.org/en/r4.3/user/downloading-installing-upgrading/installation-guide.html&quot;&gt;installation guide&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;If you’re currently using Qubes 4.2, make sure to &lt;a href=&quot;https://doc.qubes-os.org/en/r4.2/user/downloading-installing-upgrading/upgrade/4_3.html&quot;&gt;upgrade from 4.2 to 4.3&lt;/a&gt; no later than 2026-06-21, which is when &lt;a href=&quot;https://www.qubes-os.org/news/2026/04/27/qubes-os-4-2-approaching-end-of-life/&quot;&gt;4.2 will reach EOL&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;If you’re currently on Qubes 4.3 (4.3.0 or 4.3.1-rc1), &lt;a href=&quot;https://doc.qubes-os.org/en/r4.3/user/how-to-guides/how-to-update.html&quot;&gt;update normally&lt;/a&gt; (which includes &lt;a href=&quot;https://doc.qubes-os.org/en/r4.3/user/how-to-guides/how-to-update.html#upgrading-to-avoid-eol&quot;&gt;upgrading any EOL templates and standalones&lt;/a&gt; you might have) in order to make your system essentially equivalent to the stable Qubes 4.3.1 release. No reinstallation or other special action is required.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In all cases, we strongly recommend &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-back-up-restore-and-migrate.html&quot;&gt;making a full backup&lt;/a&gt; beforehand.&lt;/p&gt;

&lt;h2 id=&quot;known-issues-in-qubes-431&quot;&gt;Known issues in Qubes 4.3.1&lt;/h2&gt;

&lt;p&gt;It’s possible that templates restored in 4.3.1 from a pre-4.3 backup may continue to target their original Qubes OS release repos (&lt;a href=&quot;https://github.com/QubesOS/qubes-issues/issues/8701&quot;&gt;#8701&lt;/a&gt;). After restoring such templates in 4.3.1, enter the following additional commands in a dom0 terminal:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;sudo qubes-dom0-update -y qubes-dist-upgrade
sudo qubes-dist-upgrade --releasever=4.3 --template-standalone-upgrade -y
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;This will automatically choose the templates that need to be upgraded. The templates will be shut down during this process.&lt;/p&gt;

&lt;p&gt;Fresh templates on a clean 4.3.1 installation are not affected. Users who perform an in-place upgrade from 4.2 to 4.3 (instead of restoring templates from a backup) are also not affected, since the in-place upgrade process already includes the above fix in stage 4. For more information, see issue &lt;a href=&quot;https://github.com/QubesOS/qubes-issues/issues/8701&quot;&gt;#8701&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue%20type%3ABug%20label%3Aaffects-4.3%20-label%3A%22R%3A%20cannot%20reproduce%22%20-label%3A%22R%3A%20declined%22%20-label%3A%22R%3A%20duplicate%22%20-label%3A%22R%3A%20not%20applicable%22%20-label%3A%22R%3A%20self-closed%22%20-label%3A%22R%3A%20upstream%20issue%22&quot;&gt;View the full list of known bugs affecting Qubes 4.3&lt;/a&gt; in our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/introduction/issue-tracking.html&quot;&gt;issue tracker&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;whats-a-patch-release&quot;&gt;What’s a patch release?&lt;/h2&gt;

&lt;p&gt;The Qubes OS Project uses the &lt;a href=&quot;https://semver.org/&quot;&gt;semantic versioning&lt;/a&gt; standard. Version numbers are written as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[major].[minor].[patch]&lt;/code&gt;. Hence, we refer to releases that increment the third number as “patch releases.” A patch release does not designate a separate, new major or minor release of Qubes OS. Rather, it designates its respective major or minor release (in this case, 4.3) inclusive of all updates up to a certain point. See our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/supported-releases.html&quot;&gt;supported releases&lt;/a&gt; for a comprehensive list of major and minor releases and our &lt;a href=&quot;https://doc.qubes-os.org/en/latest/developer/releases/version-scheme.html&quot;&gt;version scheme&lt;/a&gt; documentation for more information about how Qubes OS releases are versioned.&lt;/p&gt;
</description>
        <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
        <link>https://www.qubes-os.org/news/2026/06/11/qubes-os-4-3-1-has-been-released/</link>
        <guid isPermaLink="true">https://www.qubes-os.org/news/2026/06/11/qubes-os-4-3-1-has-been-released/</guid>
        
        
        <category>releases</category>
        
      </item>
    
  </channel>
</rss>
