Description
Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure / Crash
Action: Avoid Untrusted Images
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read on the heap within dislocker's get_dataset() and get_next_datum() functions. The code fails to verify that the dataset and datum sizes reported in a BitLocker volume's metadata match the actual memory allocated, allowing a reader to access memory beyond the buffer boundaries. This can lead to program crashes or leakage of adjacent heap contents, exposing sensitive data to an attacker.

Affected Systems

The flaw affects the open‑source BitLocker unlocking utility Dislocker released by Aorimn. Specifically, version 0.7.3 and any earlier releases that retain the same get_dataset() and get_next_datum() implementation are vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires the attacker to supply a crafted BitLocker volume image to the system, which suggests the attack vector is local rather than remote. The exploit can result in denial of service and potential disclosure of confidential data contained in the adjacent heap memory.

Generated by OpenCVE AI on October 8, 2026 at 16:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Dislocker to the latest available commit that addresses the out-of-bounds read (e.g., build from the recent source revision that includes the patch).
  • If an updated release cannot be obtained, do not process untrusted BitLocker volume images with the vulnerable Dislocker utility.
  • Operate Dislocker within a tightly isolated environment such as a sandbox or container to contain any crashes or memory disclosures.

Generated by OpenCVE AI on October 8, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.
Title Dislocker through 0.7.3 Heap Out-of-Bounds Read via BitLocker Metadata Dataset Size
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:10:33.209Z

Reserved: 2026-10-08T14:05:51.476Z

Link: CVE-2026-107634

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:46.160

Modified: 2026-10-08T15:17:46.160

Link: CVE-2026-107634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:45:17Z

Weaknesses