Field Notes

source

Qubes OS Security in the Public Record

Local PDF.

A preprint by Alfonso De Gregorio, posted to arXiv on 16 July 2026, analyzing 109 public Qubes Security Bulletins (QSBs) issued between 2011 and 2025, the Qubes-maintained Xen Security Advisory (XSA) tracker, and a secondary vulnerability-event series. It is the only quantitative treatment of the Qubes OS advisory record that the wiki holds.

What it measures

The paper attributes each bulletin to a component under an audited deterministic codebook, then applies change-point analysis, overdispersion checks, severity-proxy weighting, censoring sensitivity, and baseline-aware evaluation of vulnerability discovery models (VDMs). A stratified 30-QSB audit tests the codebook’s reliability.

Principal findings:

Measure Result
QSBs attributable to upstream components 87 of 109 (79.8%)
QSBs attributable to Qubes-core logic 22 of 109 (20.2%)
XSAs affecting Qubes 113 of 464
CPU or microarchitecture bulletins 24 of 109
Transient-execution or microcode bulletins 23 of 109 (21.1%)
Transient-execution share of post-2018 bulletins 23 of 73 (31.5%)
Dominant change point in the quarterly series 2015Q1
Post-2018 annual disclosure rate Statistically flat

Twenty-three of the 24 CPU and microarchitecture bulletins are transient-execution or microcode issues, and every transient-execution advisory falls in 2018 or later. S-shaped VDMs fit the series descriptively but do not significantly outperform a rolling-mean baseline at short forecast horizons.

The limitation the paper states about itself

The study “measures the public advisory record rather than latent vulnerability incidence or realized compromise.” That sentence carries most of the note’s evidentiary weight. The record is produced by the Qubes project’s own disclosure process, so the denominator is the set of issues that project found, judged reportable, and published, not the set that existed.

This is the shape of a Correction channel: a channel’s own outputs cannot establish its own error rate, because the process generating the labels is the process whose reliability is in question. Upstream concentration in the published record is consistent with two different worlds. Qubes-core logic may really be sounder than its dependencies. Or Qubes-core may simply attract less external scrutiny than Xen and CPU microarchitecture, which are researched intensively by people who have never run Qubes. Nothing in the advisory record separates these, and the paper does not claim to. Its own summary — “stable, but not quiet” — is about disclosure activity, so a citation that converts it into a claim about how safe Qubes is has outrun the evidence.

Provenance

The preprint is 18 pages with 3 figures and 4 tables, and the author publishes supporting datasets on Zenodo. It is not peer-reviewed, it is single-authored with no institutional affiliation listed, and the wiki knows of no independent replication. Component attribution is the step most exposed to judgment, which is why the stratified audit matters, and why the codebook’s boundary cases are the first thing to check before leaning on the exact percentages.

Built on 1 source (1 external).

Working out connections…