CVE-2026-10718: Open Seachest/Seachest NVMe Trim (Deallocate) Vulnerability
Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of LBAs to deallocate 16 bytes outside of the allocated space when running this operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or avoid invoking NVMe Trim/Unmap (Deallocate) operations in openSeaChest until a vendor-supplied fix is available to prevent triggering the out-of-bounds write.
Seagate openSeaChest NVMe Trim/Unmap (Deallocate) operations = disabled / do not invoke - Compensating control
Restrict or block issuance of Trim/Unmap (Deallocate) commands to devices running openSeaChest by applying host-side controls, storage-network ACLs, SAN zoning, or WAF-like protections; limit access to trusted hosts and management interfaces only.
- Operational
Inventory and identify systems running Seagate openSeaChest v26.03.0 (the affected version) and avoid performing Trim/Unmap operations on those systems; monitor affected devices for crashes or abnormal behavior and apply vendor patches or updates when they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10718?
The severity of CVE-2026-10718 is medium with a CVSS score of 4.6.
How do I fix CVE-2026-10718?
To fix CVE-2026-10718, update Seagate's openSeaChest software to the latest version provided in their security advisories.
What kind of vulnerability is CVE-2026-10718?
CVE-2026-10718 is an out-of-bounds write vulnerability in the Trim/Unmap operation of Seagate's openSeaChest software.
Is my system affected by CVE-2026-10718?
All supported platforms running Seagate openSeaChest version 26.03.0 are potentially affected by CVE-2026-10718.
What are the potential impacts of CVE-2026-10718?
CVE-2026-10718 could lead to unauthorized memory access due to writing data outside of allocated memory space.