CVE-2026-73459: Security Advisory 0160
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Security Advisory 0160
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Affected platforms running Arista EOS are exposed when IS-IS is configured. Systems not using IS-IS are not identified as affected by the provided information.
What does an attacker need to do to exploit it?
The attacker must be able to inject a specially crafted IS-IS LSP PDU. No authentication or prior privileges are required.
What is the operational impact of successful exploitation?
A successful attack can cause a legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.