Database/Firmware, BMC & network fabric
MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the device
Impact
RouterOS accepts a "related" btest connection before the primary session has authenticated, so an unauthenticated client can start an IPv4 UDP test. With random-data=false the sender transmits an uninitialised tail from a kernel packet buffer, disclosing whatever that memory last held. A separate unchecked, inverted packet-size interval underflows an unsigned integer, producing anomalously large fragmented output and able to restart the RouterOS kernel. On a router carrying management or storage traffic for a GPU fleet, the restart is an outage on a path that is rarely redundant, and it can be triggered repeatedly. This is a distinct flaw from the SSH policy-mask escalation in the same release, though the fix versions are shared; CERT.pl reports the RouterOS set as actively exploited.
Who can reach it
Anyone who can send packets to the device's bandwidth-test service - the management network, or the internet if btest is reachable. No authentication needed.
What to do
Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable); the upgrade reboots the device, so plan for the link to drop. As an immediate mitigation, disable the bandwidth-test server (/tool bandwidth-server set enabled=no) or firewall its port to trusted sources - the advisory does not list any other workaround.
References
Related entries
- Dell OpenManage Enterprise: authenticated SQL injection exposes management database contentsCVE-2026-71176 · Dell OpenManage Enterprise (SQL injection)High
- Linux KVM - intra-host migration/mirroring of SEV-SNP VMs: KVM allowed intra-host migration and mirroring of SEV-SNPCVE-2026-72286 · Linux KVM - intra-host migration/mirroring of SEV-SNP VMsHigh
- Linux kernel (drivers/infiniband/hw/bnxt_re): The variable-WQE send-queue slot count came straight from userspace withCVE-2026-72497 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux bnxt_re RoCE driver (CQ toggle page use-after-free): The completion-queue variant of the toggle-pageCVE-2026-72499 · Linux bnxt_re RoCE driver (CQ toggle page use-after-free)High
- Linux bnxt_re RoCE driver (SRQ toggle page use-after-free): A use-after-free in the Broadcom RoCE driver — the toggleCVE-2026-72500 · Linux bnxt_re RoCE driver (SRQ toggle page use-after-free)High
- IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesCVE-2026-7868 · IBM OpenBMC (Power S1122/S1124 service processor firmware, ReadOnly role)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.