Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

SCSI defect count can overflow the defect-list allocation

CVE-2026-10717

Affected product
Seagate openSeaChest
Severity
Low · CVSS 1.8
Weakness
CWE-787
Disclosed

Summary

A large device-reported SCSI defect list could wrap the allocation calculation while leaving the original logical element count intact, leading to out-of-bounds writes and reads.

Technical analysis

The accompanying research article explains the finding, reproduction, and remediation status.

Read the technical write-up

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References