Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git . The commit identifier that contains the fix is f873b6295933e4149a2132adf3e9a2d2a676a5ec.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lwip
Lwip lwip |
|
| Vendors & Products |
Lwip
Lwip lwip |
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. | |
| Title | Double Free in lwIP (lightweight IP) | |
| Weaknesses | CWE-415 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-23T13:05:15.963Z
Reserved: 2026-09-14T16:40:45.500Z
Link: CVE-2026-91018
Updated: 2026-09-23T13:03:25.938Z
Status : Awaiting Analysis
Published: 2026-09-22T21:17:33.290
Modified: 2026-09-23T19:42:48.540
Link: CVE-2026-91018
No data.
OpenCVE Enrichment
Updated: 2026-09-23T09:00:10Z
-
CWE-415
Double Free