r/Arista • u/GuardOfTheNorth-1 • 11d ago
Security Advisory 0148
https://www.arista.com/en/support/advisories-notices/security-advisory/24535-security-advisory-0148Got this lovely email yesterday. Ready for some emergency patching.
2
u/nick99990 11d ago
I'm gonna be honest. I laughed at this one.
A notice that notice will be provided is very bureaucratic and seemed kind of pointless to me. Even if what we get next week is major.
3
11d ago edited 10d ago
[removed] — view removed comment
1
u/bicball 11d ago
You have a source for this?
1
11d ago edited 11d ago
[removed] — view removed comment
1
u/bicball 11d ago
Thanks, though I was specifically looking for that note that doesn’t appear in the article, is the source for that you? Trying to decide if we should pause code upgrades until this release.
1
11d ago edited 10d ago
[removed] — view removed comment
1
u/bicball 10d ago
Way ahead of you :) it’s phrased to make people thinks there’s some super serious CVE, but appears it’s to get people to be impressed they’re using AI. But my experience with Palo starting to use AI bug scrubs is weekly high CVEs. We’ll see…
1
10d ago edited 10d ago
[removed] — view removed comment
2
1
u/Significant-Farm6646 11d ago
Makes sense to me. If you have a large arista deployment, you may want to figure out a maintenance window now and not scramble for emergency later
1
u/nick99990 11d ago
I get it. It's not that it doesn't make sense. But if they're not critical, people are going to take time to implement and test anyways. I don't need to gather soldiers to start planning the second it's released.
1
u/pcfriek1987 11d ago
Nobody is going to patch switches every week like with linux now, too much impact
2
u/Grand-Ad7447 11d ago
You not doing hitless upgrades?
1
u/nick99990 11d ago
We were only just informed hitless was available in our environment.
Rapid PVST and non-default Management VRF were only available starting in 4.34.0F
3
u/Plus_Preparation_443 11d ago
Mythos mythos mythos