Database/Firmware, BMC & network fabric

Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every rule
Impact
If an IPv4 access list contains a VXLAN match rule, that rule and every rule after it in the list ignore the IP protocol you specified. Your ACL silently permits or denies far more than you wrote. Anyone using ACLs to keep tenant overlays apart, or to fence off a storage VLAN, is enforcing something other than what is in the config — and show access-list will not tell you.
Who can reach it
Any traffic subject to the affected ACL. No attacker capability needed beyond being on a path the ACL was supposed to control.
What to do
EOS upgrade plus reload. Immediate mitigation: reorder access lists so VXLAN match rules come last, or split them into a separate list — a live config change that restores correct enforcement of the remaining rules. Audit every ACL in the fabric for VXLAN match rules before assuming you are unaffected.
References
Related entries
- Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersCVE-2021-28508 · Arista EOS (TerminAttr / IPsec)High
- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBCVE-2021-3695 · GRUB2 (PNG reader)High
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBCVE-2021-3697 · GRUB2 (JPEG reader)High
- IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCCVE-2021-38960 · IBM OpenBMC OP920 / OP930 / OP940High
- OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportCVE-2021-39295 · OpenBMC phosphor-net-ipmid (IPMI LAN+)High
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.