Machine-generated analysis · WAYSCloud LLM
lwIP versions 2.0.1 through 2.2.1 are affected by a double-free vulnerability (CVE-2026-91018).
Context
The affected product is lwIP (Lightweight IP). The advisory states the double-free flaw could cause system crashes, denial-of-service, memory corruption, or code execution. The advisory notes deployment across many critical infrastructure sectors worldwide. A fix is provided in commit f873b6295933e4149a2132adf3e9a2d2a676a5ec.
Operator considerations
Check: Verify the lwIP version on each device and confirm it is not within 2.0.1-2.2.1.
Isolate: Limit network exposure of systems running the vulnerable lwIP stack.
Patch: Update lwIP to a version that includes commit f873b6295933e4149a2132adf3e9a2d2a676a5ec from the official repository.
Log: Monitor for unexpected crashes or memory-corruption events on affected devices.
Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.
The following versions of lwIP (Lightweight IP) are affected:
API >=2.0.1|=2.0.1|
Read the full advisory on CISA →