GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: crafted packet brings down authenticated BFD sessions and triggers routing changes

CVSS 9.2CVE-2026-73458Firmware, BMC & network fabriccurated

Impact

A crafted packet drops configured BFD sessions even when they are authenticated, and because BGP, IS-IS and other protocols use BFD as their fast liveness signal, every protocol watching that session reacts as if the link failed. The result is unwanted reconvergence across the fabric from a single remotely reachable trigger - Arista scores this 9.2 with network attack vector and no privileges. For a GPU datacenter the underlay carries RoCE/InfiniBand-adjacent traffic and storage, and BFD is deliberately tuned aggressively there, so a forced session down means immediate rerouting or blackholing and dead distributed jobs. The fact that authentication does not protect the session is the important part: the usual mitigation is already in place and does not help.

Who can reach it

Unauthenticated, network-reachable: anyone who can get the crafted packet to a switch with BFD sessions configured. BFD authentication being enabled does not prevent it.

What to do

Upgrade to the fixed EOS release or apply the hotfix from Arista security advisory 0154; an EOS upgrade means a switch reload, so stage it rack by rack with workloads drained. Because BFD authentication is not a mitigation here, the interim options are limiting which peers can reach BFD-enabled interfaces with control-plane ACLs and, where the design tolerates it, relaxing protocol dependence on BFD. Version details are in Arista's advisory only.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.