Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
https://www.arista.com/en/support/advisories-notices/security-advisories/4403-security-advisory-33