Executive brief
Seagate openSeaChest is a set of command-line utilities used by administrators to diagnose and manage storage drives. A vulnerability in the tool's defect-reporting feature could allow a malicious or severely failing drive to crash the software or potentially execute unauthorized code when a technician attempts to scan it. This risk is primarily relevant during hardware maintenance or forensic analysis of untrusted storage devices.
Technical details
An out-of-bounds (OOB) write and read vulnerability exists in Seagate openSeaChest v25.05.3 within the --showSCSIDefects command. The issue stems from improper validation of the defect response length provided by a SCSI device. An attacker can exploit this by connecting a maliciously crafted SCSI device or a drive with an exceptionally large defect list to a system running the utility. Successful exploitation requires high privileges to execute the diagnostic tool and physical or local access to the hardware interface, potentially leading to memory corruption or local code execution.
Affected products
- Seagate openSeaChest 25.05.3
Timeline
- 2026-06-02: disclosed: CVE published by Seagate Technology