On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
In order to be vulnerable to CVE-2026-73436, the following condition must be met:
OSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.
switch>show ip ospf segment-routing
SPF Instance ID: 1
...
If OSPFv2 segment routing is not configured, then there is no exposure to this issue.
No mitigation is available for CVE-2026-73436.
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.
CVE-2026-73436 has been fixed in the following releases:
- 4.36.2F and later releases in the 4.36.x train
- 4.35.6M and later releases in the 4.35.x train
- 4.34.8M and later releases in the 4.34.x train
- 4.33.10M and later releases in the 4.33.x train
No hotfix is available for CVE-2026-73436.