Qubes OS Security in the Public Record
This paper presents a longitudinal analysis of 109 Qubes Security Bulletins and related vulnerability data from 2011 to 2025, revealing that while the public advisory record has stabilized at a higher disclosure level since 2015, the security burden remains predominantly concentrated in upstream components like Xen and CPU architectures rather than Qubes' core logic.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Digital Neighborhood Watch
Imagine the internet as a giant, bustling city where every computer is a house. In most neighborhoods, the "security guard" (the operating system) lives right inside the house, watching the front door, the windows, and the backyard all at once. If the guard gets tired or makes a mistake, the whole house is in danger. But there's a special kind of house in this city called Qubes OS. Instead of one big guard, it hires a team of tiny, separate security guards, each locked inside their own glass booth (called a "qube"). If one guard gets tricked by a burglar, the other guards are safe in their booths. This is called "compartmentalization."
To know if this system is actually working, security researchers act like neighborhood watch captains. They keep a public logbook called a Security Bulletin. Every time a bug is found or a patch is needed, they write it down. The big question for this paper is: Where are the bugs actually hiding? Are they in the tiny glass booths built by the Qubes team (the "core"), or are they in the foundation of the building, the city's power grid, or the materials used to build the walls (the "upstream" parts like the computer chip and the virtualization software)? If the glass booths are perfect but the foundation is cracking, the whole house is still at risk. This study is a deep dive into fourteen years of these logbooks to see who is really doing the heavy lifting when it comes to security.
The Detective Work: Who Broke the Glass?
In this study, the author, Alfonso De Gregorio, acts like a forensic accountant for computer security. He didn't just guess; he went through every single public security bulletin for Qubes OS from 2011 to 2025. That's 109 bulletins in total, plus a tracker of 464 related issues from the underlying software (Xen) that Qubes runs on. He wanted to see if the "glass booths" (Qubes-core) were the main source of trouble, or if the trouble was coming from the "foundation" (Xen, the computer processor, and other upstream parts).
The Big Reveal: It's Not the Booths, It's the Foundation
The results were surprisingly clear. When the author looked at the 109 bulletins, he found that 79.8% of them (that's 87 out of 109) were caused by problems in the upstream parts—like the Xen hypervisor, the computer's CPU, or other software Qubes didn't write itself. Only about 20% of the issues were actually the fault of the Qubes team's own logic. Even when he weighed the problems by how many specific issues were mentioned in a bulletin, the upstream parts still dominated, accounting for over 80% of the burden.
Think of it like a car. If you buy a custom car where the engine is built by a famous company (Xen) and the body is built by a small custom shop (Qubes), and you find 80% of the problems are with the engine or the road conditions, you can't blame the custom shop for the engine trouble. The study shows that Qubes is doing a great job keeping its own small part of the code clean, but it is heavily dependent on the security of the massive, complex machinery underneath it.
The Timeline: When Did Things Change?
The author also looked at when these problems were reported. He found a major shift in early 2015. Before that, the number of security bulletins was low and sporadic. After the first quarter of 2015, the number of reports jumped up and stayed at a higher, steady level. It didn't keep climbing forever; it just leveled off.
Then, looking at the years after 2018, the data showed something interesting: the rate of new problems became "statistically flat." This doesn't mean no new bugs were found; it means the number of new bugs found per year stopped growing or shrinking significantly. It became a stable, predictable rhythm. The author also noticed that after 2018, a lot of the new problems were related to "transient execution" (a fancy term for how computer chips guess what to do next, which can sometimes leak secrets). This suggests that the nature of the threats changed, moving from simple software bugs to complex hardware-level tricks, but the amount of trouble stayed steady.
The Crystal Ball Test: Can We Predict the Future?
Finally, the author tried to use mathematical models (called Vulnerability Discovery Models or VDMs) to predict how many bugs would be found in the future. These models often look like an "S-curve," suggesting that we find a lot of bugs at first, then the rate slows down as we find all the easy ones, and eventually, we run out of bugs.
The study found that while these S-shaped curves describe the past data pretty well, they are terrible at predicting the future. When the author compared these complex models to a simple "rolling average" (basically, guessing that next year will look like the average of the last three years), the simple guess won. The complex models didn't give a better forecast. In fact, the data suggests that trying to predict exactly when the "last bug" will be found is a fool's errand; the system seems to have settled into a stable state where new issues keep appearing at a steady, manageable pace, rather than running out of them.
What This Means for You
The paper doesn't claim Qubes OS is "perfect" or "solved." It explicitly says we can't measure hidden bugs that haven't been found yet. However, it does prove that the public record of security issues is dominated by the underlying technology (Xen and the CPU) rather than the Qubes team's own code.
For anyone using this system, the lesson is practical: Don't just watch the Qubes team; watch the Xen team and the computer chip manufacturers. The "glass booths" are sturdy, but the "foundation" is where the real action is. The study confirms that the security of this system is a team effort, and the biggest risks come from the parts of the system that Qubes doesn't control directly. The authors are confident in these numbers because they checked them multiple ways, but they are also careful to say that this is a look at the public logbook, not a guarantee that no secret bugs exist in the shadows.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.