Description
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defects lists via a very bad drive with lots of defects or a maliciously crafted SCSI device’s defect response length.
Published: 2026-06-02
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an out-of-bounds write and read in the --showSCSIDefects option of Seagate’s openSeaChest tool when a very large defect list is returned by a storage device. A sufficiently large defect response, either from a drive with an extremely high defect count or from a maliciously crafted SCSI device, can cause the tool to write defect information beyond allocated memory, potentially corrupting adjacent data or causing the process to crash. The nature of the flaw is a classic buffer overflow (CWE-787). Because the tool writes data directly to memory, an attacker could potentially influence program control flow if additional conditions—such as the presence of exploitable code paths—are met.

Affected Systems

All platforms running Seagate openSeaChest version 25.05.3 are affected. The exploit targets the openSeaChest utility, part of Seagate’s software suite for managing SATA/SAS devices, and is triggered when the --showSCSIDefects flag is used with a device that returns an unusually large defect list.

Risk and Exploitability

The CVSS score of 1.8 indicates a low severity from a typical security perspective. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likelihood of exploitation is inferred to be low because it requires either a device with an abnormally large defect list or a malicious SCSI device carefully crafted to provoke the out-of-bounds write. Consequently, the risk is moderate, primarily limited to local system instability or potential denial of service if the flaw manifests in a production environment.

Generated by OpenCVE AI on June 3, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Seagate’s product‑security advisory pages for an updated openSeaChest release that addresses large defect list handling and update when available.
  • If a patch is not available, avoid invoking the --showSCSIDefects option on devices with a high defect count or from unknown vendors; restrict the command to trusted hardware.
  • Monitor system logs for memory corruption indicators or crashes during defect list retrieval and plan to replace problematic drives if instability occurs.

Generated by OpenCVE AI on June 3, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Seagate
Seagate open Seachest
Vendors & Products Seagate
Seagate open Seachest

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defects lists via a very bad drive with lots of defects or a maliciously crafted SCSI device’s defect response length.
Title Open-Seachest/Seachest show SCSI Defect List Vulnerability
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:Y/R:A/V:D/RE:L/U:Clear'}


Subscriptions

Seagate Open Seachest
cve-icon MITRE

Status: PUBLISHED

Assigner: Seagate

Published:

Updated: 2026-06-03T13:01:19.297Z

Reserved: 2026-06-02T22:00:45.727Z

Link: CVE-2026-10717

cve-icon Vulnrichment

Updated: 2026-06-03T13:01:15.806Z

cve-icon NVD

Status : Received

Published: 2026-06-02T23:16:34.987

Modified: 2026-06-02T23:16:34.987

Link: CVE-2026-10717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T10:54:29Z

Weaknesses