Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git . The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. | |
| Title | Double Free in lwIP (lightweight IP) | |
| Weaknesses | CWE-415 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-22T20:25:33.530Z
Reserved: 2026-09-14T16:40:45.500Z
Link: CVE-2026-91018
No data.
Status : Received
Published: 2026-09-22T21:17:33.290
Modified: 2026-09-22T21:17:33.290
Link: CVE-2026-91018
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:30:20Z