CVE-2026-107635
Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
| CWE | CWE-191 |
| Vendor | aorimn |
| Product | dislocker |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for aorimn dislocker
Be the first to know when new medium vulnerabilities affecting aorimn dislocker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Aorimn / dislocker
0 โค 0.7.3
References
github.com: https://github.com/Aorimn/dislocker/commit/0706462db88efe8df88150e4c3e4332b808f4581 github.com: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/vmk.c#L146-L180 github.com: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/fvek.c#L90-L105 github.com: https://github.com/Aorimn/dislocker vulncheck.com: https://www.vulncheck.com/advisories/dislocker-through-0.7.3-out-of-bounds-heap-read-via-vmk-fvek-datum-size-underflow
Credits
Tristan Madani (@TristanInSec), Talence Security