GHSA-v459-vrm9-x34fMediumCVSS 5.5

Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek()...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.

🔗 References (7)