CVE-2026-73436: Security Advisory 0171
On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOS (OSPFv2 with segment routing)to a version that resolves this vulnerability.Fixed in 4.33.10M and later releases in the 4.33.x train - Upgrade
Upgrade
Arista EOS (OSPFv2 with segment routing)to a version that resolves this vulnerability.Fixed in 4.34.8M and later releases in the 4.34.x train - Upgrade
Upgrade
Arista EOS (OSPFv2 with segment routing)to a version that resolves this vulnerability.Fixed in 4.35.6M and later releases in the 4.35.x train - Upgrade
Upgrade
Arista EOS (OSPFv2 with segment routing)to a version that resolves this vulnerability.Fixed in 4.36.2F and later releases in the 4.36.x train
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Affected platforms running Arista EOS are exposed when both OSPFv2 and OSPFv2 segment routing are configured.
What access does an attacker need to trigger the issue?
An attacker needs to be an adjacent OSPF neighbor and send a specially crafted OSPFv2 packet. No privileges or user interaction are required according to the supplied severity vector.
What is the expected impact if exploitation succeeds?
OSPF may restart unexpectedly, causing an availability impact. The supplied severity vector indicates no confidentiality or integrity impact.