PT-2026-97043 · Lwip · Lwip

·

CVE-2026-91018

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lwIP versions 2.0.1 through 2.2.1
Description A double free vulnerability exists in the lwIP API, which occurs when the system attempts to free the same memory location twice. This flaw can lead to system crashes, denial of service, memory corruption, or arbitrary code execution on the victim system. The issue affects critical infrastructure worldwide, including chemical, energy, financial services, healthcare, transportation, and water systems. Real-world incidents have been observed where attackers exploited this flaw to gain initial access to critical infrastructure, using memory corruption to achieve privilege escalation and lateral movement across unencrypted OT (Operational Technology) networks.
Recommendations Update lwIP versions 2.0.1 through 2.2.1 to a newer version that contains a fix. Implement runtime segmentation to contain post-compromise activity in industrial environments.

Fix

LPE

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91018

Affected Products

Lwip