CVE-2026-2379: Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting in sequence number mismatches between tunnel endpoints potentially causing unstable communication.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2379?
CVE-2026-2379 has a medium severity rating of 5.9.
How do I fix CVE-2026-2379?
To resolve CVE-2026-2379, upgrade to a remediated software version of Arista EOS.
What impact does CVE-2026-2379 have on my system?
CVE-2026-2379 may cause unexpected behavior in IPsec tunnels when certain conditions are met, particularly during interface flaps.
Is CVE-2026-2379 specific to any hardware?
Yes, CVE-2026-2379 affects platforms with hardware IPSec support running Arista EOS.
What should I do if I experience issues related to CVE-2026-2379?
If you encounter issues related to CVE-2026-2379, it is recommended to upgrade to the latest version of Arista EOS to avoid potential vulnerabilities.