GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast traffic

CVSS 7.1CVE-2026-73468Firmware, BMC & network fabriccurated

Impact

A specially crafted packet causes multicast forwarding state on affected interfaces to expire before it should, so multicast traffic is lost until the state is rebuilt. Arista's description is brief and does not name the protocol or the packet, so the exposure should be read as what it says: an availability hit to multicast forwarding, not a path to the switch. Where multicast carries cluster discovery, storage heartbeats or telemetry between GPU nodes, an intermittent drop shows up as job-level failures that are hard to attribute to the fabric. This is a different defect from the IGMP snooping agent crash in advisory 0159 and carries its own advisory.

Who can reach it

Network-adjacent and unauthenticated per the CVSS vector (AV:A) - a host able to send traffic onto an affected interface. Authentication on the switch is not required.

What to do

Follow Arista advisory 0175 for the affected platforms and fixed EOS releases. The advisory does not, in the record here, name a configuration workaround, so plan an EOS upgrade on affected switches and schedule it against the racks those switches feed.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.