CVE-2026-107634: Dislocker through 0.7.3 Heap Out-of-Bounds Read via BitLocker Metadata Dataset Size
Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in getdataset() and getnextdatum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users or systems that open or mount BitLocker volume images with Dislocker through 0.7.3 are exposed, particularly when processing images from untrusted sources.
What must an attacker provide to exploit it?
An attacker needs to craft a BitLocker volume image whose metadata contains inflated dataset or datum sizes, and induce a user or process to open or mount that image with Dislocker.
What is the practical impact of successful exploitation?
Processing the crafted image can crash Dislocker and may disclose adjacent heap memory. The supplied severity vector indicates local attack access and required user interaction.