CVE-2026-10717: Open-Seachest/Seachest show SCSI Defect List Vulnerability

Published Jun 2, 2026
·
Updated

Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defects lists via a very bad drive with lots of defects or a maliciously crafted SCSI device’s defect response length.

Affected Software

1 affected component
Seagate openSeaChest=25.05.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Seagate/openSeaChest v25.05.3 from your environment.

    Uninstall openSeaChest v25.05.3 if the tool or the --showSCSIDefects feature is not required, or replace it with an alternative until a patched release is provided.

  2. Configuration

    Do not invoke the --showSCSIDefects option in openSeaChest v25.05.3 until a vendor patch is available; avoid running this option against untrusted or potentially malicious SCSI devices.

    Seagate openSeaChest --showSCSIDefects = disable / do not use
  3. Compensating control

    Restrict access to SCSI devices and interfaces: only connect and allow responses from trusted SCSI devices and hosts, and isolate or quarantine untrusted devices to prevent malicious defect responses.

  4. Operational

    If --showSCSIDefects has been run against untrusted or suspicious devices, cease use of the affected tool and inspect systems and storage for crashes or data corruption; do not use affected devices until they are validated or a patch is applied.

Event History

Jun 2, 2026
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10717?

The severity of CVE-2026-10717 is classified as low with a score of 1.8 on the CVSS scale.

2

How do I fix CVE-2026-10717?

To fix CVE-2026-10717, it is recommended to update to the latest version of Seagate's openSeaChest software.

3

What are the potential impacts of CVE-2026-10717?

CVE-2026-10717 can allow for out of bounds write and reads, potentially leading to data corruption or system instability.

4

Which versions of Seagate openSeaChest are affected by CVE-2026-10717?

CVE-2026-10717 affects all supported platforms running Seagate openSeaChest v25.05.3.

5

Is CVE-2026-10717 exploitable remotely?

Yes, CVE-2026-10717 is exploitable locally through a compromised or maliciously crafted SCSI device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203