Database/Firmware, BMC & network fabric

Arista EOS and CVX: malformed CVX cluster messages crash the Sysdb agent and soft-reset the switch
Impact
In a CVX cluster, neither side validates the messages it receives from its peer. A malformed message from the CVX server crashes the Sysdb agent on the EOS switch, which soft-resets the switch; a malformed message in the other direction crashes agents on the CVX server and destabilises the cluster. On a GPU fabric a leaf or spine soft-reset drops the links carrying tenant traffic and collective communication, so training jobs spanning the affected switch fail rather than degrade. Switches not connected to a CVX server are unaffected. Exploitation requires high-privilege access to one of the devices already, which puts this in the blast-radius-of-a-compromised-switch category rather than the perimeter category.
Who can reach it
An attacker who already holds high-privilege access on an EOS switch or on the CVX server, and can therefore send custom TCP packets over the CVX control connection. Authenticated, on the management/control path.
What to do
Follow Arista security advisory 0126 for fixed EOS and CVX versions and the hotfix it offers; the record given here does not name a fixed version, so take it from the advisory. Operationally, the containment lever available today is to limit who can reach and administer the CVX control connection - the attack needs privileged access on one end. An EOS upgrade on a fabric switch means taking that switch out of the fabric, so plan it with the usual leaf/spine drain.
References
Related entries
- Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the clusterCVE-2025-5090 · Arista CloudVision eXchange (CVX) server - switch message handlingHigh
- Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANsCVE-2026-19655 · Arista EOS DHCP relay (Option 82 information option handling)High
- Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationCVE-2026-20293 · Cisco UCS server BIOS (UEFI Shell)High
- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayCVE-2026-31395 · Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler)High
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.