lwIP (Lightweight IP)
Summary
A double free vulnerability has been identified in specific versions of lwIP (Lightweight IP), potentially leading to system crashes, denial of service, memory corruption, or even code execution on affected systems. The vulnerability, identified as CVE-2026-91018, impacts lwIP API versions greater than or equal to 2.0.1 and less than or equal to 2.2.1.
IFF Assessment
This vulnerability poses a significant risk to defenders as successful exploitation can lead to denial of service and code execution.
Severity
The CVSS score of 8.8 (HIGH) is derived from a CVSS v3.1 vector indicating an attack vector of Adjacent (AV:A), low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), unchanged scope (S:U), and high impact on Confidentiality (C:H), Integrity (I:H), and Availability (A:H).
Defender Context
This vulnerability in the widely used lwIP (Lightweight IP) stack, which is prevalent in critical infrastructure sectors, requires immediate attention. Defenders should prioritize patching or implementing mitigations for affected versions to prevent potential denial-of-service attacks and code execution.