PT-2026-107993 · Aorimn · Dislocker

CVE-2026-107634

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get dataset() and get next datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107634

Affected Products

Dislocker