Description
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow vulnerability in MikroTik RouterOS Release 7.21.x versions earlier than 7.21.4 and 7.22.x earlier than 7.22.2 allows an attacker to force the "unflatten()" function in libumsg.so to crash, resulting in a complete restart of the RouterOS service. The failure interrupts network services and can lead to significant disruption in environments that rely on continuous routing or firewall protection. The weakness is a classic integer overflow that corrupts memory during IPC message processing.

Affected Systems

The affected products are MikroTik RouterOS operating systems. Specifically, all RouterOS Release 7.21.x versions preceding 7.21.4 and all RouterOS Release 7.22.x versions preceding 7.22.2 are impacted. No earlier releases are affected, and all releases after 7.22.2 include the patch.

Risk and Exploitability

The CVSS score is 7.5. The EPSS score is less than 1%, indicating a low yet nonzero likelihood of exploitation. Based on the description, it is inferred that the vulnerability can be exploited remotely, requiring the attacker to send a crafted IPC message over the network. Because the attack can be performed from any external host and does not require elevated privileges, its potential impact is significant for exposed devices. The vulnerability is not listed in the CISA KEV catalog. This combination of moderate-to-high severity, low exploitation probability, and negative impact on availability underscores the need for timely patching.

Generated by OpenCVE AI on July 31, 2026 at 12:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MikroTik RouterOS to version 7.21.4 or later, or 7.22.2 or later, as released by MikroTik to fix the unflatten() integer overflow.
  • If an immediate upgrade is infeasible, isolate the affected device from external traffic or disable IPC services that rely on libumsg.so until a patch is applied.
  • Monitor system logs for unexpected crashes or restarts and temporarily block or filter traffic to IPC ports until a patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Integer Overflow in MikroTik RouterOS IPC

Wed, 29 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Integer Overflow in MikroTik RouterOS IPC

Sat, 25 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in RouterOS IPC Unflatten Function Causes Remote DoS

Fri, 24 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in RouterOS IPC Unflatten Function Causes Remote DoS

Mon, 20 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in MikroTik RouterOS unflatten() Function Causes Remote Denial of Service

Thu, 16 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in MikroTik RouterOS unflatten() Function Causes Remote Denial of Service

Tue, 14 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros

Mon, 13 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
References

Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-14T16:27:12.476Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39042

cve-icon Vulnrichment

Updated: 2026-07-14T16:25:02.357Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:30:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound