CVE-2026-10717
Out-of-Bounds Write in Seagate openSeaChest
Publication date: 2026-06-02
Last updated on: 2026-06-02
Assigner: Seagate Technology
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| seagate | openseachest | 25.05.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves out of bounds write and read operations in the --showSCSIDefects feature of Seagate's openSeaChest version 25.05.3. It occurs when handling very large defect lists from a very bad drive with many defects or from a maliciously crafted SCSI device that provides an abnormal defect response length.
How can this vulnerability impact me? :
The vulnerability allows writing defect information out of bounds, which can lead to memory corruption. This could potentially cause unexpected behavior or crashes in the openSeaChest software when processing defect lists from drives or SCSI devices.