CVE-2026-107634 — Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datu…
Description
Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.
CVSS v4.0 base metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/Aorimn/dislocker
- advisory[email protected]https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/datums.c#L589-L640
- advisory[email protected]https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/metadata.c#L764-L790
- advisory[email protected]https://github.com/Aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48
- advisory[email protected]https://www.vulncheck.com/advisories/dislocker-through-0.7.3-heap-out-of-bounds-read-via-bitlocker-metadata-dataset-size
Related threats
same CWE or vendorCVE-2026-82334 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser.
CVE-2026-82334 · 2h ago
CVE-2026-106428 — An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing…
CVE-2026-106428 · 3h ago
CVE-2026-107302 — msgpack5 is a msgpack v5 implementation for node.js and the browser.
CVE-2026-107302 · 4h ago
CVE-2026-14988 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to…
CVE-2026-14988 · 7h ago
CVE-2026-14496 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-14496 · 7h ago
CVE-2026-16161 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-16161 · 8h ago