CVE-2026-91018
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-91018 is a double free vulnerability in lwIP (Lightweight IP), a lightweight TCP/IP stack widely used in embedded and IoT systems. It affects lwIP API versions 2.0.1 through 2.2.1 and was publicly disclosed on September 22, 2026, via a CISA ICS Advisory (ICSA-26-265-02). The vulnerability was reported by Eric Evenchick of Tetrel Security. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (CISA Advisory, Github Advisory).

Détails techniques

The vulnerability is classified as CWE-415 (Double Free) and CWE-1341 (Multiple Releases of Same Resource or Handle), occurring when the lwIP stack frees the same memory address twice, leading to heap corruption. An unauthenticated attacker on an adjacent network can trigger this condition without any user interaction or special privileges. The fix is available as a specific commit (f873b6295933e4149a2132adf3e9a2d2a676a5ec) in the official lwIP repository. No detailed public technical write-up or proof-of-concept code has been published as of the disclosure date (CISA Advisory, Github Advisory).

Impact

Successful exploitation can result in a system crash, denial of service (DoS), memory corruption, or arbitrary code execution on the affected system. Given that lwIP is broadly deployed across critical infrastructure sectors — including Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare, Transportation, and Water/Wastewater Systems — the potential blast radius is significant. An attacker achieving code execution could pivot to further compromise embedded or OT/ICS devices on the same network segment (CISA Advisory).

Exploitabilité

No public proof-of-concept exploit code exists, and no in-the-wild exploitation has been reported as of the disclosure date. CISA explicitly notes that no known public exploitation specifically targeting this vulnerability has been reported, and the vulnerability is not exploitable remotely (requires adjacent network access). The EPSS score is 0.0, reflecting the current absence of observed exploitation activity. The vulnerability has not been added to the CISA KEV catalog (CISA Advisory, Github Advisory).

Atténuation et solutions de contournement

Users of lwIP should update to a version of the library newer than 2.2.1 by pulling from the official repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git, specifically applying commit f873b6295933e4149a2132adf3e9a2d2a676a5ec which contains the fix. If immediate patching is not feasible, CISA recommends implementing network segmentation to restrict adjacent network access to systems running vulnerable lwIP versions, placing control system networks behind firewalls, and using VPNs for any required remote access. Additionally, minimize network exposure for all affected control system devices and ensure they are not accessible from the internet (CISA Advisory, Github Advisory).

Réactions de la communauté

CISA issued ICS Advisory ICSA-26-265-02 on September 22, 2026, highlighting the vulnerability's relevance across multiple critical infrastructure sectors worldwide. Red Hat opened a Bugzilla tracking entry (Bug 2538918) to assess impact on their products. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (CISA Advisory, Red Hat Bugzilla).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

lwip

Affecté

sid

lwip

Affecté

trixie

lwip

Affecté

Ubuntu

Inconnu

devel

lwip

Inconnu

focal (esm-apps)

lwip

Inconnu

jammy

lwip

Inconnu

jammy (esm-apps)

lwip

Inconnu

noble

lwip

Inconnu

noble (esm-apps)

lwip

Inconnu

resolute

lwip

Inconnu

resolute (esm-apps)

lwip

Inconnu

SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-91018HIGH8.7
  • Linux Debian logoLinux Debian
  • lwip
NonNonSep 22, 2026
CVE-2026-91777HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NonNonSep 23, 2026
CVE-2026-91776HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NonNonSep 23, 2026
CVE-2026-89425HIGH7.5
  • Linux Debian logoLinux Debian
  • pki-ca
NonNonSep 23, 2026
CVE-2026-82331NONEN/A
  • Linux Debian logoLinux Debian
  • buildstream
NonNonSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités