We’re pleased to announce the stable release of Qubes OS 4.3.1! This patch release aims to consolidate all the security updates and bug fixes that have occurred since the previous stable release. Our goal is to provide a secure and convenient way for users to install (or reinstall) the latest stable Qubes release with an up-to-date ISO. The ISO and associated verification files are available on the downloads page.
Qubes OS User Survey 2026 is now live! Whether you’re a long-time Qubes user or haven’t even installed it yet, we want to hear about your experiences and about what matters to you. Help us make Qubes the best reasonably secure operating system it can be. The survey takes 10-20 minutes and is fully anonymous. We do not collect any data except for the answers you provide. If you’ve ever wanted to influence the development of Qubes, now is your chance. Make your voice heard!
If you’d like to install Qubes for the first time or perform a clean reinstallation on an existing system, there’s never been a better time to do so! Simply download the Qubes 4.3.1 ISO and follow our installation guide.
If you’re currently on Qubes 4.3 (4.3.0 or 4.3.1-rc1), update normally (which includes upgrading any EOL templates and standalones you might have) in order to make your system essentially equivalent to the stable Qubes 4.3.1 release. No reinstallation or other special action is required.
It’s possible that templates restored in 4.3.1 from a pre-4.3 backup may continue to target their original Qubes OS release repos (#8701). After restoring such templates in 4.3.1, enter the following additional commands in a dom0 terminal:
This will automatically choose the templates that need to be upgraded. The templates will be shut down during this process.
Fresh templates on a clean 4.3.1 installation are not affected. Users who perform an in-place upgrade from 4.2 to 4.3 (instead of restoring templates from a backup) are also not affected, since the in-place upgrade process already includes the above fix in stage 4. For more information, see issue #8701.
The Qubes OS Project uses the semantic versioning standard. Version numbers are written as [major].[minor].[patch]. Hence, we refer to releases that increment the third number as “patch releases.” A patch release does not designate a separate, new major or minor release of Qubes OS. Rather, it designates its respective major or minor release (in this case, 4.3) inclusive of all updates up to a certain point. See our supported releases for a comprehensive list of major and minor releases and our version scheme documentation for more information about how Qubes OS releases are versioned.
After downloading the R4.3.1 iso and the PGP signature, I get the message “faulty signature” when trying to verify the download. This happens when using Kleopatra and a commercial PGP implementation.
Also, I noticed that the verification files for version R4.3.0 were Qubes-R4.3.0-x86_64.iso.asc containing the PGP signature, and Qubes-R4.3.0-x86_64.iso.DIGESTS containing a signed list of hash values, whereas here only one file Qubes-R4.3.1-x86_64.iso.DIGESTS.asc is provided, which looks like a signature, but does not match.
@balko asked for a log of changes between 4.3.0 and 4.3.1, whereas it looks like you might have misread that as a request for a log of changes between 4.3.1-rc1 and 4.3.1.
However, even if the request had been for a log of changes between 4.3.1-rc1 and 4.3.1, it’s important to understand that there are no changes between the final RC and the stable release. In fact, the entire point of having RCs is to test the very same release before declaring it stable. Once the devs have decided that an RC is good enough to be declared stable, that very same ISO is designated (essentially relabeled) as the stable release with no further changes made to it, because if any further changes were made, another round of testing would be required (which would be -rc2) to ensure that the new changes didn’t introduce any new bugs.
This is why the 4.3.1 announcement already includes the same link as the one from the 4.3.1-rc1 announcement: Because the list of changes is exactly the same.
Aaaah yes. I knew it was not everything in 4.3.1 final, only later stuff. And if I had thought about it, I might have contemplated the lack of a later rc.
I might even have found the link in the announcement, which I spotted 30 minutes ago, while it was downloading…
Sigh.
It depends on the purpose for which you intend to use them. They’re consistent in the sense that I make sure every issue has exactly one priority label, but it could be the case that a lot of the “defaults” just haven’t been assigned their “true” priority yet by a dev who’s qualified to make that determination, and sometimes I increase the priority of an issue based on vague-but-better-than-nothing criteria like whether a lot of users seem to be affected by an issue.
I was wondering about the “Change Log with major changes or fixes”, it could be a way to sort issues: high priority, default and minor. But I’m not convinced.
I remembered reading in the survey about NixOS and Devuan templates. But I can’t find them anywhere. I would like to use them. Are those there only to move towards bright Nix and Devuan templates future or those are real options one can use now without creating them manually?
Thanks for all the hard work people!
I succesfully upgraded from 4.2 with the upgrade tool. (--skip-standalone-upgrade was necessary or it would hard fail at trying to upgrade Windows standalones.)
The new tray icons are really nice, but now the sys-net WiFi icon has become an eyesore