Database/Firmware, BMC & network fabric

Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the cluster
Impact
The CVX server does not handle unexpected messages from a connected switch, and the resulting agent crashes make the CVX cluster unstable. CVX is the control service the fabric leans on for shared state; losing it does not black-hole traffic by itself, but it takes away the coordination layer operators use to manage the fabric and can leave the cluster flapping until it is restored. Tracked separately from CVE-2025-5089, which also covers the reverse direction and the Sysdb agent crash on the switch itself - the affected side and the failure differ, so the two are listed on their own. Reaching this requires high-privilege access on a connected switch.
Who can reach it
An attacker with high-privilege access on a switch already connected to CVX, able to send custom TCP packets to the CVX server. Authenticated, from inside the fabric control path.
What to do
Upgrade the CVX server to a fixed version per Arista security advisory 0126 (fixed versions are in the advisory, not in the record here) and restart the CVX service; CVX runs as a service or VM, so this does not require touching the switches. A compromised or misbehaving switch is the precondition, so restricting switch administrative access limits exposure in the interim.
References
Related entries
- Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANsCVE-2026-19655 · Arista EOS DHCP relay (Option 82 information option handling)High
- Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationCVE-2026-20293 · Cisco UCS server BIOS (UEFI Shell)High
- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayCVE-2026-31395 · Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler)High
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightCVE-2026-45856 · Linux kernel InfiniBand core (ib_uverbs post_send)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.