Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory. | |
| Title | Dislocker through 0.7.3 Heap Out-of-Bounds Read via BitLocker Metadata Dataset Size | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T14:10:33.209Z
Reserved: 2026-10-08T14:05:51.476Z
Link: CVE-2026-107634
No data.
Status : Received
Published: 2026-10-08T15:17:46.160
Modified: 2026-10-08T15:17:46.160
Link: CVE-2026-107634
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:45:17Z
-
CWE-125
Out-of-bounds Read