CVE-2026-107635
EUVD-2026-9502208.10.2026, 15:17
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References