CVE-2026-107635: Aorimn Dislocker
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Affected products
- Aorimn Dislocker: up to and including 0.7.3
Published 2026-10-08. Last modified 2026-10-08.