PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107634 Aorimn CVE debrief

A heap out-of-bounds read vulnerability exists in Dislocker through version 0.7.3. The vulnerability is caused by a lack of validation of dataset and datum sizes against the metadata allocation in the get_dataset() and get_next_datum() functions. An attacker can craft a BitLocker volume image with inflated dataset or datum sizes, which, when opened or mounted, can cause dislocker to crash or disclose adjacent heap memory.

Vendor
Aorimn
Product
dislocker
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using Dislocker, particularly those handling BitLocker volume images, should assess exposure and prioritize patching or upgrading to a fixed version.

Why it matters

Defenders should care about CVE-2026-107634 because it can be exploited to cause a crash or potentially disclose sensitive information in Dislocker through version 0.7.3. The vulnerability requires validation of dataset and datum sizes against the metadata allocation to prevent exploitation.

  • Potential disclosure of adjacent heap memory
  • Crash or denial of service when opening or mounting a crafted BitLocker volume image

Technical summary

The vulnerability exists in the get_dataset() and get_next_datum() functions, which do not validate dataset and datum sizes against the metadata allocation. An attacker can craft a BitLocker volume image with inflated dataset or datum sizes to exploit the vulnerability. This can cause dislocker to crash or disclose adjacent heap memory. Defenders should prioritize patching or upgrading to a fixed version of Dislocker, as the vulnerability can be exploited to cause a crash or potentially disclose sensitive information. The CVE Program record and NVD vulnerability detail page provide official information about the vulnerability.

Defensive priority

Defenders should prioritize patching or upgrading to a fixed version of Dislocker, as the vulnerability can be exploited to cause a crash or potentially disclose sensitive information.

Recommended defensive actions

  • Patch or upgrade to a fixed version of Dislocker
  • Review and validate input data to prevent exploitation
  • Monitor for potential crashes or disclosure of sensitive information
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is confirmed to exist in Dislocker through version 0.7.3. The CVE Program record and NVD vulnerability detail page provide official information about the vulnerability. Additional technical details can be found in the source item and supplemental source references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107634 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107634

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107634 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107634

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Dislocker through 0.7.3 Heap Out-of-Bounds Read via BitLocker Metadata Dataset Size

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107634.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/commit/9158e9e41dd669b360cbc53cc18ccae729b67b48

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/metadata.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/datums.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/dislocker-through-0.7.3-heap-out-of-bounds-read-via-bitlocker-metadata-dataset-size

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.