CVE-2026-73436 PUBLISHED

Security Advisory 0171

Assigner: Arista
Reserved: 12.08.2026 Published: 16.09.2026 Updated: 16.09.2026

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor Arista Networks
Product EOS
Versions Default: unaffected
  • affected from 4.36.0F to 4.36.1F (incl.)
  • affected from 4.35.0F to 4.35.5M (incl.)
  • affected from 4.34.0F to 4.34.7.1M (incl.)
  • affected from 4.33.0F to 4.33.9M (incl.)
  • affected from 1.0.0 to 4.33.0F (excl.)

Affected Configurations

In order to be vulnerable to CVE-2026-73436, the following condition must be met:

OSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.

switch>show ip ospf segment-routing SPF Instance ID: 1 ...

If OSPFv2 segment routing is not configured, then there is no exposure to this issue.

Workarounds

No mitigation is available for CVE-2026-73436.

Solutions

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.

CVE-2026-73436 has been fixed in the following releases: - 4.36.2F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.8M and later releases in the 4.34.x train - 4.33.10M and later releases in the 4.33.x train

No hotfix is available for CVE-2026-73436.

References

Problem Types

  • CWE-1284 Improper Validation of Specified Quantity in Input CWE
  • CWE-125 Out-of-bounds Read CWE