Impact
Dislocker, an open‑source tool for mounting BitLocker volumes, contains an integer underflow in the get_vmk() and get_fvek() parsing routines that can cause an out‑of‑bounds heap read when a datum_size field is smaller than the required 36‑byte AES‑CCM header. The underflow converts the small size into a large unsigned value, leading the hexdump routine to read beyond the allocated buffer and ultimately crash the dislocker process, resulting in a denial of service.
Affected Systems
The affected product is Dislocker maintained by Aorimn. All releases up through version 0.7.3 are vulnerable. The flaw is triggered when the application processes a BitLocker volume image containing an improperly sized datum; any user running dislocker locally with an untrusted or manipulated image on any supported platform is impacted.
Risk and Exploitability
The base CVSS score of 6.8 reflects a medium‑severity denial‑of‑service risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local or an available‑file attack: an attacker can supply a crafted BitLocker image through a medium such as a USB drive or network share. The flaw does not disclose data or provide privilege escalation; it only disrupts the tool’s normal operation.
OpenCVE Enrichment