lwIP TCP/IP stack double-free vulnerability disclosed
A double-free flaw in lwIP versions 2.0.1-2.2.1 could crash embedded/ICS devices or lead to code execution; no known in-the-wild exploitation and not remotely exploitable.
CISA published an ICS advisory for a double-free vulnerability (CVE-2026-91018, CWE-415) in lwIP (Lightweight IP), a widely embedded TCP/IP stack used across critical infrastructure sectors including Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, and Water/Wastewater Systems. lwIP is deployed worldwide and maintained by a Sweden-headquartered project.
The flaw affects lwIP API versions >=2.0.1 and <=2.2.1. Successful exploitation could result in a system crash, denial of service, memory corruption, or potentially code execution on the affected device. CISA notes the vulnerability is not remotely exploitable, and no public exploitation has been reported at this time. The issue was responsibly reported by Eric Evenchick of Tetrel Security.
A fix is available via the upstream lwIP git repository (commit f873b6295933e4149a2132adf3e9a2d2a676a5ec). CISA recommends organizations update affected lwIP deployments, minimize network exposure of control system devices, isolate ICS networks behind firewalls, and use secure remote access methods such as VPNs where required. Given the embedded nature of lwIP, defenders should inventory devices/firmware using this stack and coordinate patching through vendor firmware updates.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free