CVE-2026-67277: Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Lont-term), 7.23.4 (Lont-term) and 7.24.2 (Stable)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.49.21Patch Lont-term - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.23.4Patch Lont-term - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.24.2Patch Stable - Configuration
If performing an IPv4 UDP test using RouterOS btest, ensure random-data is not set to "false" because it can transmit an uninitialized tail from a kernel packet buffer.
MikroTik RouterOS btest service random-data = false