Impact
The vulnerability is an out‑of‑bounds read on the heap within dislocker's get_dataset() and get_next_datum() functions. The code fails to verify that the dataset and datum sizes reported in a BitLocker volume's metadata match the actual memory allocated, allowing a reader to access memory beyond the buffer boundaries. This can lead to program crashes or leakage of adjacent heap contents, exposing sensitive data to an attacker.
Affected Systems
The flaw affects the open‑source BitLocker unlocking utility Dislocker released by Aorimn. Specifically, version 0.7.3 and any earlier releases that retain the same get_dataset() and get_next_datum() implementation are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires the attacker to supply a crafted BitLocker volume image to the system, which suggests the attack vector is local rather than remote. The exploit can result in denial of service and potential disclosure of confidential data contained in the adjacent heap memory.
OpenCVE Enrichment