CVE-2026-107634: Aorimn Dislocker
Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory.
Affected products
- Aorimn Dislocker: up to and including 0.7.3
Published 2026-10-08. Last modified 2026-10-10.