v3.2.9 — OpenSSL 3.5.9, the first-boot box finishes setup, Dual WAN backup shown, USB format works
- OpenSSL 3.5.9: CVE-2026-84782 (High). The DTLS retransmission logic resumed a suspended
handshake write from a stale buffer offset, so a retransmission could disclose heap memory to the
peer or crash. Also fixed, all Low: CVE-2026-35189 (relative CRLDP memory growth), CVE-2026-35191
(QUIC amplification credit), CVE-2026-42772 (QUIC O(n²) reassembly), CVE-2026-54872 (non-NIST EC
scalar-multiplication timing), CVE-2026-54873 (QUIC STREAM fragment memory). Taken from the release
tarball (signature verified) with the two carried differences of the 3.5.8 import (RSDNTWK): the
Broadcom build targets inConfigurations/10-main.confand no empty submodule directories. Same
library SONAME; the closed components still reach it through the 1.1 shim. - IPv6: CVE-2023-52340. Forged ICMPv6 Packet Too Big messages, accepted from the WAN, each add
a route-cache exception; past the 4,096net.ipv6.route.max_sizedefault,dst_alloc()fails
and neighbour discovery stops, taking IPv6 down. rc now setsmax_sizetoINT_MAXat boot, the
same change as mainlineaf6d10345ca7; the GC and exception expiry still bound the cache. Only
boxes with IPv6 enabled were exposed. - e2fsprogs 1.45.6: CVE-2022-1304. An extent-tree leaf with zero entries sent libext2fs out of
bounds; the disk check (e2fsck, run on a USB app-folder disk at mount, from the USB page and on schedule)
could be attacked with a crafted disk. Upstreamab51d587bb9b(1.46.6) applied. - First-boot setup box: the main network is usable on the Network page. The banner's box wrote
the radios and Smart Connect but never ran the SDN reconcile, so a factory box kept its single
default profile row until some later SDN apply, and the Network page's main card could not be
opened (adding a guest network was the workaround, because that apply is the reconcile). The box's
CGI now callssync_apgx_to_wlunit()before it commits and the page's apply ends inrestart_sdn,
the order every stock SDN writer uses. - USB Format and Scan reach the right disk (field, RT-BE86U). The page posted
diskmon_usbport
throughstart_apply, which rewrites everydiskmon_*key, so the port never reached rc: Format
did nothing anddisk_monitorthen crashed on a missing disk. The page now sets the port through
change_diskmon_unitand reads it back before scanning or formatting (which also stops a two-disk
box acting on the wrong disk);start_diskformatreturns cleanly when the disk is gone and reports
a failed format; the scan says when a FAT/exFAT volume cannot be checked. - Dynamic puncturing survives a wireless restart (field, GT-BE98).
restart_wirelessnever
stoppedrpunctd, so the controller kept arming measurement windows through the radio teardown and
a dongle radio could die until reboot. It is now stopped before the radios go down and started after
they are ready, and it touches no radio while they are not. - Dual WAN: the backup line is shown and lit. The Dashboard read unit 0 only; it now follows
wan_primary, so a fail-over shows the backup line as connected with its address. The WAN LED
logic is in a closed ASUS object that lights white only for the WAN port; a connected backup line
now lights the LED red and white together, red alone while it is down, and the stock logic repaints
it on fail-back. - Rules engine. A group, zone or zone-policy list longer than the engine takes used to drop the
rest silently; each cap now logs once per ruleset and the page refuses it at save. The confirmed
snapshot on/jffsis written in full before any file is replaced, a boot that finds snapshot files
without their completion marker re-adopts them instead of saving empty lists over them, and a save
that fails (a full/jffs) keeps the draft and says so. - Warden applies in one batch. Its rules are restored with one
iptables-restore --noflushper
stack instead of one command per rule, with a per-rule fallback. - Rule Status tests a rule from its own zone. A rules-engine witness entered from the LAN bridge
whatever zone the rule named, so a VLAN-only drop was judged by the stock LAN accept and a VLAN-only
accept could read OK without being tested. It now enters on the rule's source zone from that
subnet and aims at the router's address there, or at the destination zone for a forward rule; a zone
with no live interface gives no row (reaper_fwsim1.7). Report only; no rule changes. - AiMesh: "Ethernet Backhaul Mode" is now "Ethernet-Only Backhaul". The setting forbids the
wireless fallback; wired backhaul already works with it off. - Diagnostics v1.3.24 adds roaming, scheduler, DFS and auth/PMF settings, roamast and radar event
counts, and a warning when the log store is in RAM while a USB disk is attached. - Dictionaries. 4 tokens added and 4 relabelled in all 25 packs.
Images & checksums (RT-BE86U)
Two flashable images: + AI Advisor (default) and Standard (noMCP, all AI components compiled out entirely). Flash the *_nand_squashfs.pkgtb via Administration > Firmware Upgrade.
This is a beta release. Its filename carries
_BETAand the router reports the same string on the dashboard and the About page, so you can always tell which channel a flashed image came from. Stable releases carry no marker.
| Variant | File | SHA-256 |
|---|---|---|
| + AI Advisor | RT-BE86U_3006_102.8_Reaper_v3.2.9_BETA_nand_squashfs.pkgtb
| 87175f23828613ce152a755fba674231eece18239100d055675214a5984bf401
|
| Standard | RT-BE86U_3006_102.8_Reaper_v3.2.9_BETA_noMCP_nand_squashfs.pkgtb
| 987ad4760e7f7b2818f9592d53cad347d37054fc5b2b8e7b9b6005939a132900
|
Verify a download against the attached SHA256SUMS-RT-BE86U-Reaper_v3.2.9.txt.
Corresponding source & reproducibility
The RT-BE86U image for v3.2.9-beta is built from this repository at tag v3.2.9-beta-RT-BE86U: the pinned Asuswrt-Merlin base (3006.102.8-beta2, a7ebfa133a) plus the complete patch series. The tag freezes the exact source that produced it.
- Patches:
patches/ - Provenance record:
provenance/manifest.json - How to verify:
docs/REPRODUCIBILITY.mdanddocs/SOURCE-AVAILABILITY.md
The auto-attached Source code (zip/tar.gz) asset below is this repository at tag v3.2.9-beta-RT-BE86U (patches + docs).