CVE-2026-91018: Double Free in lwIP (lightweight IP)
Published Sep 22, 2026
·Updated
lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
Affected Software
1 affected component
lwIP lwIP (Lightweight IP)
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lwIP (Lightweight IP)to a version that resolves this vulnerability.Patch f873b6295933e4149a2132adf3e9a2d2a676a5ec
Event History
Sep 22, 2026
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates adjacent-network access is required. No privileges or user interaction are required, and attack complexity is low.
2
What could successful exploitation cause?
Successful exploitation could crash the system, cause a denial of service, corrupt memory, or allow code execution on the affected system. The reported impact is high for confidentiality, integrity, and availability.