On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
In order to be vulnerable to CVE-2026-73435, all of the following conditions must be met:
- The vulnerable OSPFv2 instance must have at least two neighbors on the same interface.
- The interface is a broadcast interface.
- OSPFv2 cryptographic authentication is configured.
No mitigation is available for CVE-2026-73435.
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.
CVE-2026-73435 has been fixed in the following releases:
- 4.36.2F and later releases in the 4.36.x train
- 4.35.6M and later releases in the 4.35.x train
- 4.34.7.1M and later releases in the 4.34.x train
- 4.33.10M and later releases in the 4.33.x train
A hotfix is available for the following releases: 4.36.1F, 4.35.5M, 4.34.7M, 4.33.9M.
URL: https://www.arista.com/support/advisories-notices/sa-download/?sa171-SecurityAdvisory171_CVE-2026-73435.swix
SWIX hash (SHA512): 4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7
Note: Installing/uninstalling the SWIX will cause the Ospf process to restart.