IM
IronMonkey Threat Research
‹ Back to ICS Advisories

lwIP (Lightweight IP)

HIGH
CVSS 8.8
Date 2026-09-22T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-91018 8.8 high
The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

// Remediations (1)

Mitigation: Users of lwIP are encouraged to update their version of lwIP using the repository found at https://c
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git. The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.

// References