{"id":"CVE-2026-107634","summary":"Dislocker through 0.7.3 Heap Out-of-Bounds Read via BitLocker Metadata Dataset Size","details":"Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.","modified":"2026-10-11T07:05:42.842648652Z","published":"2026-10-08T14:10:33.209Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107634.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107634.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107634"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dislocker-through-0.7.3-heap-out-of-bounds-read-via-bitlocker-metadata-dataset-size"},{"type":"FIX","url":"https://github.com/Aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48"},{"type":"PACKAGE","url":"https://github.com/Aorimn/dislocker"},{"type":"ARTICLE","url":"https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/datums.c#L589-L640"},{"type":"ARTICLE","url":"https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/metadata.c#L764-L790"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aorimn/dislocker","events":[{"introduced":"0"},{"fixed":"6662821483d953bf23464ffd64d100d0b8dc3e4c"},{"fixed":"9158e9e41dd669b360cbc53cc18ccae729b67b48"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.7.3"}]}}],"versions":["v0.7.2","v0.7.1","v0.7","v0.6.1","v0.6","v0.5.2","v0.5.1","v0.5","v0.4.1","v0.4","v0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107634.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"130313810530963511655904081360354967663","length":987},"id":"CVE-2026-107634-3a4b7803","signature_type":"Function","signature_version":"v1","source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48","target":{"function":"get_next_datum","file":"src/metadata/datums.c"}},{"signature_version":"v1","source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48","target":{"file":"src/metadata/datums.c","function":"get_nested_datumvaluetype"},"deprecated":false,"digest":{"function_hash":"206645296117331481233993099946322444562","length":491},"id":"CVE-2026-107634-66454d57","signature_type":"Function"},{"target":{"file":"src/metadata/datums.c"},"deprecated":false,"digest":{"line_hashes":["22386303622752867088135483617881618264","326067977726564317598675384019219181132","98072133099483465630293253351783248807","204493172710265328624365106987994593725","220672336529387809093490787437101798154","237268251690581518459987435709718407593","201256641350758782173608756458574141178","144409866471796268897619505113485648042","149372526171971764838604474540487694673","196937548148331217866207837522030181350","331659314046505678782582806139092970461","262782798573166579469152053694258911439","222466806957190343732605076607249688375","66031119064173436612542448437217564367","330665232234148318271266993782065193368","79591689053322004033003466864596055749","137673970093461400885753248736053945495","177186573434101542391181463470409485422","237671962761393206326070455508105485774","258343837699343726286763679128629134959","328661731713741180713428592432626693756","257426660733333799616847625879574736570","172309975438645457518666471793562864136","215337370220916398673867215403704655881","105135349804760838859480469610730392589","209294049095180529083420733682144232464"],"threshold":0.9},"id":"CVE-2026-107634-7565f6c9","signature_type":"Line","signature_version":"v1","source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48"},{"source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48","target":{"file":"src/metadata/datums.c","function":"get_nested_datum"},"deprecated":false,"digest":{"length":420,"function_hash":"26338446106534961748177733958062408589"},"id":"CVE-2026-107634-7fe4eb5f","signature_type":"Function","signature_version":"v1"},{"digest":{"length":415,"function_hash":"12845886161184175514731607848139235286"},"id":"CVE-2026-107634-840a536e","signature_type":"Function","signature_version":"v1","source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48","target":{"file":"src/metadata/metadata.c","function":"get_dataset"},"deprecated":false},{"source":"https://github.com/aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48","target":{"file":"src/metadata/metadata.c"},"deprecated":false,"digest":{"line_hashes":["73493617869583276977003681994292207864","38712580568428928719551183376677288186","93547659322174383783748959342417720650","331615002106055195555821283325946987973","142134184811752888880031685384367360243","63679016693312529229224373584426035497","197996323894678535569329771080208974765","278812624143669479353384973944385215961","232095819603390866802107235567952426795","98387840536553101470089012464196767107","127803864507179763534064190302135855764","163775496283739205780187425261768615276","121155794601567509593789190378870991924","267116958758810641475302264651616222571"],"threshold":0.9},"id":"CVE-2026-107634-a5896ca2","signature_type":"Line","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-11T07:05:42Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"}]}