CVE-2026-10717: Open-Seachest/Seachest show SCSI Defect List Vulnerability
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defects lists via a very bad drive with lots of defects or a maliciously crafted SCSI device’s defect response length.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Seagate/openSeaChest v25.05.3from your environment.Uninstall openSeaChest v25.05.3 if the tool or the --showSCSIDefects feature is not required, or replace it with an alternative until a patched release is provided.
- Configuration
Do not invoke the --showSCSIDefects option in openSeaChest v25.05.3 until a vendor patch is available; avoid running this option against untrusted or potentially malicious SCSI devices.
Seagate openSeaChest --showSCSIDefects = disable / do not use - Compensating control
Restrict access to SCSI devices and interfaces: only connect and allow responses from trusted SCSI devices and hosts, and isolate or quarantine untrusted devices to prevent malicious defect responses.
- Operational
If --showSCSIDefects has been run against untrusted or suspicious devices, cease use of the affected tool and inspect systems and storage for crashes or data corruption; do not use affected devices until they are validated or a patch is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10717?
The severity of CVE-2026-10717 is classified as low with a score of 1.8 on the CVSS scale.
How do I fix CVE-2026-10717?
To fix CVE-2026-10717, it is recommended to update to the latest version of Seagate's openSeaChest software.
What are the potential impacts of CVE-2026-10717?
CVE-2026-10717 can allow for out of bounds write and reads, potentially leading to data corruption or system instability.
Which versions of Seagate openSeaChest are affected by CVE-2026-10717?
CVE-2026-10717 affects all supported platforms running Seagate openSeaChest v25.05.3.
Is CVE-2026-10717 exploitable remotely?
Yes, CVE-2026-10717 is exploitable locally through a compromised or maliciously crafted SCSI device.