PT-2026-107994 · Aorimn · Dislocker

CVE-2026-107635

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Dislocker through 0.7.3 contains an integer underflow vulnerability in get vmk() and get fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.

Correção

Integer Underflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107635

Produtos afetados

Dislocker