CVE-2026-10719: Open Seachest/Seachest NVMe show Format Descriptors Vulnerability
Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory which sets a value to 1 via a maliciously crafted NVMe device with a bogus value in the namespace FLBAS byte.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Seagate/openSeaChest v25.05.3from your environment.Uninstall or do not deploy Seagate openSeaChest v25.05.3 on systems that may accept untrusted or malicious NVMe devices. Remove this version until a vendor-provided patch or fixed release is published.
- Configuration
Do not run openSeaChest with the --showSupportedFormats option (which is where the out-of-bounds write occurs). Avoid invoking that feature in environments using Seagate openSeaChest v25.05.3 until an official fix is available.
openSeaChest --showSupportedFormats = disabled / do not run
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10719?
CVE-2026-10719 has a low severity rating of 1.8 on the CVSS scale.
What is CVE-2026-10719 about?
CVE-2026-10719 describes an out of bounds write vulnerability in Seagate's openSeaChest that allows for writing an extra byte outside of allocated memory.
How do I fix CVE-2026-10719?
To fix CVE-2026-10719, update to the latest version of Seagate openSeaChest that addresses this vulnerability.
What can potentially exploit CVE-2026-10719?
CVE-2026-10719 can be exploited through a maliciously crafted NVMe device that sends a bogus value in the namespace FLBAS byte.
What platforms are affected by CVE-2026-10719?
CVE-2026-10719 affects all supported platforms running Seagate openSeaChest version 25.05.3.