PatchSiren cyber security CVE debrief
CVE-2026-107635 Aorimn CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T14:10:33.744Z and has not been modified since then. Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Defenders should assess exposure and prioritize patching to prevent potential out-of-bounds heap reads. The vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK.
- Vendor
- Aorimn
- Product
- dislocker
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using Dislocker versions up to 0.7.3 should assess exposure and prioritize patching to prevent potential out-of-bounds heap reads. This includes reviewing and updating inventory to ensure Dislocker versions are up-to-date and monitoring for potential exploitation attempts. Security teams should verify and apply patches, review compensating controls, and track exceptions.
Why it matters
CVE-2026-107635 allows attackers to trigger out-of-bounds heap reads in Dislocker through 0.7.3 via crafted datum sizes, requiring defenders to verify and apply patches.
- Verify patch application to prevent exploitation
- Assess exposure of Dislocker versions up to 0.7.3 in the environment
- Monitor for potential exploitation attempts
Technical summary
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. The vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK. The official CVE Program record and NIST NVD detail page offer additional vulnerability metadata. Supplied references provide additional context on the vulnerability and patching guidance for Dislocker versions up to 0.7.3. The vulnerability was introduced in Dislocker versions up to 0.7.3.
Defensive priority
Defenders should prioritize verifying and applying the patch for Dislocker versions up to 0.7.3, as the vulnerability allows for out-of-bounds heap reads via crafted datum sizes in VMK/FVEK.
Recommended defensive actions
- Verify and apply the patch for Dislocker versions up to 0.7.3
- Review and update inventory to ensure Dislocker versions are up-to-date
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the integer underflow vulnerability in Dislocker through 0.7.3, which allows attackers to trigger out-of-bounds heap reads. The official CVE Program record and NIST NVD detail page offer additional vulnerability metadata. The vulnerability was introduced in Dislocker versions up to 0.7.3. There are no known exploits in the wild, but defenders should verify and apply patches. Supplied references provide additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107635 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107635
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107635 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107635
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Dislocker through 0.7.3 Out-of-Bounds Heap Read via VMK/FVEK Datum Size Underflow
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107635.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Aorimn/dislocker/commit/0706462db88efe8df88150e4c3e4332b808f4581
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/vmk.c
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/Aorimn/dislocker/blob/v0.7.3/src/metadata/fvek.c
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/Aorimn/dislocker
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/dislocker-through-0.7.3-out-of-bounds-heap-read-via-vmk-fvek-datum-size-underflow
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.