Arista EOS 4.33.0F introduced per-VRF support for RFC 5837 Extended ICMP Errors on all platforms except containerized EOS (cEOS). Operators can restrict the feature with an ACL; ICMP error extensions can expose interface identifiers, interface names, MTU values, and IP addresses to compatible traceroute tools. Testing also found optional Node ID extension codepoints apparently carrying a hostname, which triggered Wireshark parsing failures; packet captures and device configurations were published for review.
Tooling support is developing alongside the network implementation. traceroute 2.1.4, included with Ubuntu 24.04 LTS and Debian Trixie, supports RFC 5837 via its -e option, while Trippy can show unknown extensions in ICMP-extension mode. Feature requests backed by production captures were filed for Trippy and the Rust-based ttl traceroute and path-monitoring tool, which already provides MPLS-label parsing, ECMP detection, path-MTU discovery, and export and Prometheus-oriented monitoring capabilities.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Lukas Tribus documented that Arista EOS supports RFC 5837 Extended ICMP Errors from EOS 4.33.0F on all platforms except cEOS. He published packet captures and configurations from testing, reported Wireshark parsing failures with optional Node ID extension codepoints, and filed implementation requests with Trippy and ttl.
Lukas Tribus stated that feature requests based on production traceroute captures had been filed for Trippy and ttl. He noted that Trippy can display unknown extensions in ICMP-extension mode and that traceroute 2.1.4 supports RFC 5837 via its -e option, including in Ubuntu 24.04 LTS and Debian Trixie.
Bryan Holloway stated that Arista EOS added RFC 5837 extended-ICMP-error support for non-default VRFs in EOS 4.35.2F. He said the feature is enabled per VRF and can be restricted with access-control lists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.