lwIP (Lightweight IP)
CISA warns lwIP 2.0.1–2.2.1 has a double-free that can crash devices or enable code execution.
CISA ICS advisory ICSA-26-265-02 covers CVE-2026-91018, a double-free (CWE-415) in lwIP API versions 2.0.1 through 2.2.1. Successful exploitation could crash the system, cause a denial of service or memory corruption, or lead to code execution. CVSS v3.1 is 8.8 High and CVSS v4.0 is 8.7 High, with an adjacent-network vector; CISA says it is not remotely exploitable. Eric Evenchick of Tetrel Security reported it, and CISA says no known public exploitation has been reported.
46