CVE-2026-73460

Summary

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0 <= 4.36.1Faffected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

Workarounds

No workaround is available for this issue.

References