{"id":"CVE-2026-107635","summary":"Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow","details":"Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.","modified":"2026-10-09T02:49:22.647065602Z","published":"2026-10-08T14:10:33.744Z","database_specific":{"cwe_ids":["CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107635.json","cna_assigner":"VulnCheck"},"references":[{"type":"PACKAGE","url":"https://github.com/Aorimn/dislocker"},{"type":"ARTICLE","url":"https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/fvek.c#L90-L105"},{"type":"ARTICLE","url":"https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/vmk.c#L146-L180"},{"type":"FIX","url":"https://github.com/Aorimn/dislocker/commit/0706462db88efe8df88150e4c3e4332b808f4581"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107635.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107635"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dislocker-through-0.7.3-out-of-bounds-heap-read-via-vmk-fvek-datum-size-underflow"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aorimn/dislocker","events":[{"introduced":"0"},{"last_affected":"6662821483d953bf23464ffd64d100d0b8dc3e4c"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"0.7.3"}]}}],"versions":["v0.7.3","v0.7.2","v0.7.1","v0.7","v0.6.1","v0.6","v0.5.2","v0.5.1","v0.5","v0.4.1","v0.4","v0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107635.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}