Database/Firmware, BMC & network fabric

Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-based
Impact
IPv4 packets carrying IP options can bypass policy-based routing, BGP Flowspec and interface traffic policy redirection. If you use PBR or Flowspec to steer a tenant's traffic through an inspection or scrubbing path, an attacker sets an IP option and goes around it. Flowspec-based DDoS mitigation on the cluster edge fails the same way.
Who can reach it
Any sender able to emit IPv4 packets with IP options toward an interface with the affected redirection configured.
What to do
EOS upgrade plus reload. Interim: drop IPv4 packets with IP options at the edge with an ACL — a live config change, and reasonable policy in a datacenter fabric where IP options have no legitimate use.
References
Related entries
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
- AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soCVE-2023-34472 · AMI MegaRAC SPx (BMC web interface, HTTP header handling)Medium
- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPCVE-2024-21981 · AMD Secure Processor - cryptographic key usage controlMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.