View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected: API >=2.0.1|<=2.2.1 (CVE-2026-91018) CVSS Vendor Equipment Vulnerabilities v3 8.8 lwIP lwIP (Lightweight IP) Double Free Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-91018 The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. View CVE Details Affected Products lwIP (Lightweight IP) Vendor: lwIP Product Version: lwIP API: >=2.0.1|<=2.2.1 Product Status: known_affected Remediations Mitigation Users of lwIP are encouraged to update their version of lwIP using the repository found at https://cgit.git.savannah.gnu.org/cgit/lwip.git. The commit identifier that contains the f…
Open the source record- Tags
- CISA, healthcare
- Related exam domains
- CISSP 8: Software Development Security; CISM 2: Information Security Risk Management
- Source record id
- /node/25522
- First seen by InfoSec Signals
- 9/23/2026
Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.