← Back to search

CVE-2026-91018

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The lwIP library contains a double free vulnerability that could lead to system crashes, denial of service, memory corruption, or code execution.
Exploitability
Exploitation requires the attacker to trigger the double free condition, which could be challenging without specific knowledge of the application's memory management.
Blast radius
If exploited, the vulnerability could impact the entire system, leading to service disruption or unauthorized code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to lwIP version 2.1.3 or later.
rcememory-corruptiondoslibrary-vuln

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-415

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.