GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane traffic

CVSS 5.3CVE-2025-7048Firmware, BMC & network fabriccurated

Impact

On Arista EOS platforms with MACsec configured, a specially crafted packet makes the MACsec process terminate; sustained delivery of such packets causes longer-term dataplane disruption. MACsec is what encrypts datacenter interconnect and leaf-spine links, including the links carrying storage and east-west training traffic between GPU halls. Losing the dataplane on those links stalls distributed training jobs and can fail collective operations across the whole allocation, and a repeated crash keeps the link down rather than flapping once. No code execution or data disclosure is claimed - this is availability only, scoped to adjacent-network reach.

Who can reach it

Adjacent network - an attacker who can put packets onto a link terminating on an affected EOS switch with MACsec configured. No authentication required.

What to do

Apply the EOS version or hotfix listed in Arista security advisory 0132. Arista publishes hitless hotfix patches for many such issues; where only a full EOS upgrade applies, the switch reloads, so plan it per-switch against your fabric redundancy - on a non-redundant spine that is a fabric maintenance window. Only platforms with MACsec configured are exposed, so confirm your configuration before scheduling.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.