Executive brief
Arista EOS network switches are vulnerable to a denial-of-service attack via malformed IGMP (multicast management) packets. An attacker on the same network can crash the IGMP snooping service, causing multicast traffic to flood all network ports until the service restarts. Repeated attacks could sustain prolonged disruption of multicast traffic management.
Technical details
An out-of-bounds read (CWE-125) in the IGMP snooping agent of Arista EOS allows a network-adjacent, unauthenticated attacker to send specially crafted IGMP packets on an affected VLAN. The malformed packets trigger a crash of the IGMP snooping service (signal 11), temporarily disabling multicast traffic management and causing multicast packets to be flooded to all VLAN ports until the service recovers. IGMP snooping is enabled by default on all VLANs; no special configuration is required for exploitation. Arista has released fixed versions in all supported release trains: 4.36.2F+, 4.35.6M+, 4.34.8M+, and 4.33.9M+. No workaround or hotfix is available; upgrade is the only mitigation.
Affected products
- Arista EOS 4.36.1F and earlier in 4.36.x, 4.35.5M and earlier in 4.35.x, 4.34.7.1M and earlier in 4.34.x, 4.33.8M and earlier in 4.33.x, and all prior releases
Timeline
- 2026-09-16: disclosed
- 2026-09-09: advisory: Arista Security Advisory 0159 published