CVE-2024-7095: On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being term
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is restarted) and memory pressure for other processes on the switch. Increased memory pressure can cause processes other than snmpd to be at risk for unexpected termination as well.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7095?
The severity of CVE-2024-7095 is classified as high due to potential memory leaks that can lead to the termination of the snmpd process.
How do I fix CVE-2024-7095?
To fix CVE-2024-7095, it is recommended to review and modify the SNMP configuration, particularly adjusting the 'snmp-server transmit max-size' parameter.
What platforms are affected by CVE-2024-7095?
CVE-2024-7095 affects platforms running Arista EOS with SNMP configured.
What are the potential impacts of CVE-2024-7095?
The potential impacts of CVE-2024-7095 include memory leaks in the snmpd process that could lead to denial of service.
Is there a workaround for CVE-2024-7095?
A possible workaround for CVE-2024-7095 includes changing the SNMP configuration parameters to mitigate the risk of memory leaks.