GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: crafted IS-IS Hello PDU tears down an established adjacency on a broadcast link

CVSS 7.0CVE-2026-73446Firmware, BMC & network fabriccurated

Impact

An attacker on the same L2 segment as a switch running IS-IS on a broadcast interface can drop an established adjacency, withdrawing every prefix learned across it. On a GPU fleet the IS-IS underlay is what carries storage traffic and east-west RDMA/RoCE routing between leaf and spine, so a dropped adjacency reroutes or blackholes traffic for whole racks at once. Long-running distributed training jobs do not survive a routing flap gracefully - collectives stall or abort, and the loss is fleet-wide rather than per-tenant. No confidentiality or integrity loss is claimed, only availability of reachability.

Who can reach it

Unauthenticated attacker with adjacent-network access - anything that can put frames on a broadcast segment where the switch runs IS-IS. No credentials required.

What to do

Apply the fixed EOS release or hotfix named in Arista security advisory 0160; an EOS upgrade means a scheduled switch reload (or ISSU where the platform supports it), so drain or dual-home the affected racks first. Until then, restrict which ports can carry IS-IS and enable IS-IS authentication where the design allows. Arista's advisory is the only source for affected and fixed versions; nothing further is stated in the record.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.