Description
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Dislocker, an open‑source tool for mounting BitLocker volumes, contains an integer underflow in the get_vmk() and get_fvek() parsing routines that can cause an out‑of‑bounds heap read when a datum_size field is smaller than the required 36‑byte AES‑CCM header. The underflow converts the small size into a large unsigned value, leading the hexdump routine to read beyond the allocated buffer and ultimately crash the dislocker process, resulting in a denial of service.

Affected Systems

The affected product is Dislocker maintained by Aorimn. All releases up through version 0.7.3 are vulnerable. The flaw is triggered when the application processes a BitLocker volume image containing an improperly sized datum; any user running dislocker locally with an untrusted or manipulated image on any supported platform is impacted.

Risk and Exploitability

The base CVSS score of 6.8 reflects a medium‑severity denial‑of‑service risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local or an available‑file attack: an attacker can supply a crafted BitLocker image through a medium such as a USB drive or network share. The flaw does not disclose data or provide privilege escalation; it only disrupts the tool’s normal operation.

Generated by OpenCVE AI on October 8, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dislocker to a version that includes the fix (e.g., 0.7.4 or later).
  • If an upgrade is not immediately possible, avoid processing BitLocker images from untrusted or unknown sources and verify the integrity of the image before passing it to dislocker.
  • Run dislocker in a sandboxed environment—such as a container or virtual machine—to isolate any crash from the host system.
  • Consider implementing a file‑integrity check, using a cryptographic hash or digital signature, on BitLocker images before processing to mitigate the risk of the underflow trigger.

Generated by OpenCVE AI on October 8, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Title Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T16:05:30.813Z

Reserved: 2026-10-08T14:05:59.396Z

Link: CVE-2026-107635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:46.340

Modified: 2026-10-08T16:17:04.623

Link: CVE-2026-107635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)