Database/Firmware, BMC & network fabric

Arista EOS OSPFv3: crafted packet restarts the routing agent
Impact
A specially crafted packet makes the OSPFv3 agent restart unexpectedly. This is availability only - no code execution and no disclosure - but a routing agent that flaps takes adjacencies down with it, and on a GPU fabric that means collectives stall and multi-node training jobs fail rather than degrade. If the packet can be replayed the switch can be kept in a restart loop. Only switches with OSPFv3 configured are affected, which in most GPU datacenters means the routed underlay rather than the storage or management segments.
Who can reach it
Anyone who can deliver OSPFv3 packets to an affected switch - in practice an adjacent device or anything that can inject onto a segment where OSPFv3 is running. No authentication required.
What to do
Confirm which switches actually run OSPFv3 and apply OSPFv3 authentication and interface-level filtering so only intended neighbours can send. Take the fixed EOS release or hotfix from Arista security advisory 0173 and upgrade on a per-switch window; the record does not name a fixed version.
References
Related entries
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationCVE-2014-8159 · Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c)High
- Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes theCVE-2016-5685 · Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injectionHigh
- Cisco NX-OS / FXOS (LLDP parser): A malformed LLDP frame reloads the switch. LLDP is enabled by default on essentiallyCVE-2018-0395 · Cisco NX-OS / FXOS (LLDP parser)High
- Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who alreadyCVE-2018-1244 · Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent)High
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminCVE-2018-15774 · Dell iDRAC9 (Redfish)High
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeCVE-2018-3628 · Intel AMT (HTTP handler) in Intel CSME firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.