Executive brief
Seagate openSeaChest is a set of command-line utilities used for managing and diagnosing storage drives. A vulnerability in the way it handles certain drive information could allow a maliciously crafted storage device to cause a minor memory error when a user runs specific diagnostic commands. While this could theoretically lead to unexpected behavior, the risk is low as it requires physical or administrative access to attach a specialized malicious device.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the --showSupportedFormats function of Seagate openSeaChest v25.05.3. The flaw is triggered by a maliciously crafted NVMe device that provides a bogus value in the namespace Format LBA Size (FLBAS) byte. This causes the application to write one extra byte (setting a value to 1) outside of the allocated memory buffer. Exploitation requires local access and high privileges to interface with the hardware device, and the impact is limited to minor integrity and availability issues.
Affected products
- Seagate openSeaChest 25.05.3
Timeline
- 2026-06-02: disclosed: Initial publication of the CVE record