On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloudeos | Arista | 4.26.0 (including) | 4.26.9m (excluding) |
Cloudeos | Arista | 4.27.0 (including) | 4.27.8m (excluding) |
Cloudeos | Arista | 4.28.0 (including) | 4.28.5m (excluding) |
Cloudeos | Arista | 4.29.0 (including) | 4.29.2f (excluding) |