CVE-2026-107635: Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow
Dislocker through 0.7.3 contains an integer underflow vulnerability in getvmk() and getfvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datumsize smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Affected Software
Event History
Frequently Asked Questions
What must an attacker provide to trigger the issue?
An attacker must supply a malicious BitLocker volume image containing a VMK or FVEK datum_size smaller than the 36-byte AES-CCM header. Processing that image can cause hexdump() to read beyond the heap buffer.
What is the practical impact of successful exploitation?
The stated impact is an out-of-bounds heap read that can crash dislocker, resulting in a denial of service. The provided data does not describe confidentiality or integrity impact.
Which versions are affected?
Dislocker through version 0.7.3 is affected.