PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107635 Aorimn CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T14:10:33.744Z and has not been modified since then. Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Defenders should assess exposure and prioritize patching to prevent potential out-of-bounds heap reads. The vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK.

Vendor
Aorimn
Product
dislocker
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using Dislocker versions up to 0.7.3 should assess exposure and prioritize patching to prevent potential out-of-bounds heap reads. This includes reviewing and updating inventory to ensure Dislocker versions are up-to-date and monitoring for potential exploitation attempts. Security teams should verify and apply patches, review compensating controls, and track exceptions.

Why it matters

CVE-2026-107635 allows attackers to trigger out-of-bounds heap reads in Dislocker through 0.7.3 via crafted datum sizes, requiring defenders to verify and apply patches.

  • Verify patch application to prevent exploitation
  • Assess exposure of Dislocker versions up to 0.7.3 in the environment
  • Monitor for potential exploitation attempts

Technical summary

Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. The vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK. The official CVE Program record and NIST NVD detail page offer additional vulnerability metadata. Supplied references provide additional context on the vulnerability and patching guidance for Dislocker versions up to 0.7.3. The vulnerability was introduced in Dislocker versions up to 0.7.3.

Defensive priority

Defenders should prioritize verifying and applying the patch for Dislocker versions up to 0.7.3, as the vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK.

Recommended defensive actions

  • Verify and apply the patch for Dislocker versions up to 0.7.3
  • Review and update inventory to ensure Dislocker versions are up-to-date
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the integer underflow vulnerability in Dislocker through 0.7.3, which allows attackers to trigger out-of-bounds heap reads. The official CVE Program record and NIST NVD detail page offer additional vulnerability metadata. The vulnerability was introduced in Dislocker versions up to 0.7.3. There are no known exploits in the wild, but defenders should verify and apply patches. Supplied references provide additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107635 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107635

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107635 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107635

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107635.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/commit/0706462db88efe8df88150e4c3e4332b808f4581

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/vmk.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/fvek.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Aorimn/dislocker

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/dislocker-through-0.7.3-out-of-bounds-heap-read-via-vmk-fvek-datum-size-underflow

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.