Database/Firmware, BMC & network fabric

Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANs
Impact
An unauthenticated device on a client-facing VLAN can crash and restart the DHCP relay agent on an EOS switch. On a cluster where GPU nodes, BMCs or storage hosts get their addressing through relay on that switch, the outage window means nodes that reboot or renew a lease during the restart come up without an address. Nothing is disclosed or modified - the record describes availability loss only. The exposure exists only where relay/snooping is configured with Option 82, or where the DHCP server matches on the information option.
Who can reach it
Anyone with unauthenticated layer 2 access to a VLAN where the relay is configured - in practice a tenant or host port on the switch, not the management network.
What to do
Apply the fixed EOS release or the hotfix listed in Arista security advisory 0155; the advisory is the authority on affected trains and fixed versions, and this record does not name one. As a configuration mitigation, the relay is only exposed where Option 82 handling is enabled. Plan the change as a switch maintenance window - a leaf switch upgrade drains traffic for every node behind it unless the fabric is dual-homed.
References
Related entries
- Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationCVE-2026-20293 · Cisco UCS server BIOS (UEFI Shell)High
- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayCVE-2026-31395 · Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler)High
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightCVE-2026-45856 · Linux kernel InfiniBand core (ib_uverbs post_send)High
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenCVE-2026-53187 · Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.