CVE-2026-73460: Security Advisory 0160
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Platforms running Arista EOS are exposed when IS-IS graceful restart is enabled and an attacker can inject malformed IS-IS LSP PDU packets.
What does an attacker need to exploit it?
The attacker does not need authentication, but must be able to inject a malformed IS-IS LSP PDU packet. Exploitation requires high attack complexity.
What is the operational impact?
The IS-IS graceful restart procedure can terminate prematurely, which may cause traffic loss after a restart event.
What mitigation is indicated by the available information?
The available information identifies IS-IS graceful restart being enabled as a prerequisite. It does not provide a patch version, workaround, or detection method.