CVE-2025-8873: Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BUG603398 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BUG1246592 - Configuration
On affected platforms with IPsec configured, create/apply the TCAM profile for ipsec-egress-padding-removal and set it as the system profile (run `hardware tcam`, then `system profile ipsec-egress-padding-removal`).
Arista EOS hardware TCAM system profile ipsec-egress-padding-removal = enabled - Compensating control
Expect/plan for forwarding agent(s) to exit and restart when the TCAM profile changes; after reset, traffic may momentarily not resume processing for all traffic through the forwarding chip managed by the restarting agent(s).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8873?
The severity of CVE-2025-8873 is rated high with a CVSS score of 7.5.
How does CVE-2025-8873 affect Arista EOS?
CVE-2025-8873 allows a specially crafted IPsec packet to cause the dataplane to stop processing all IPsec traffic, potentially leading to a denial of service.
How do I fix CVE-2025-8873?
To fix CVE-2025-8873, upgrade to the latest remediated version of Arista EOS as recommended.
What are the consequences of CVE-2025-8873?
The consequence of CVE-2025-8873 is that it may disrupt IPsec traffic processing, which can significantly impact network operations.
Is there a known workaround for CVE-2025-8873?
There are no known workarounds for CVE-2025-8873; upgrading is the recommended solution.