
PEACH
Un cadre d’isolation des locataires
CVE-2026-91018 is a double free vulnerability in lwIP (Lightweight IP), a lightweight TCP/IP stack widely used in embedded and IoT systems. It affects lwIP API versions 2.0.1 through 2.2.1 and was publicly disclosed on September 22, 2026, via a CISA ICS Advisory (ICSA-26-265-02). The vulnerability was reported by Eric Evenchick of Tetrel Security. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (CISA Advisory, Github Advisory).
The vulnerability is classified as CWE-415 (Double Free) and CWE-1341 (Multiple Releases of Same Resource or Handle), occurring when the lwIP stack frees the same memory address twice, leading to heap corruption. An unauthenticated attacker on an adjacent network can trigger this condition without any user interaction or special privileges. The fix is available as a specific commit (f873b6295933e4149a2132adf3e9a2d2a676a5ec) in the official lwIP repository. No detailed public technical write-up or proof-of-concept code has been published as of the disclosure date (CISA Advisory, Github Advisory).
Successful exploitation can result in a system crash, denial of service (DoS), memory corruption, or arbitrary code execution on the affected system. Given that lwIP is broadly deployed across critical infrastructure sectors — including Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare, Transportation, and Water/Wastewater Systems — the potential blast radius is significant. An attacker achieving code execution could pivot to further compromise embedded or OT/ICS devices on the same network segment (CISA Advisory).
No public proof-of-concept exploit code exists, and no in-the-wild exploitation has been reported as of the disclosure date. CISA explicitly notes that no known public exploitation specifically targeting this vulnerability has been reported, and the vulnerability is not exploitable remotely (requires adjacent network access). The EPSS score is 0.0, reflecting the current absence of observed exploitation activity. The vulnerability has not been added to the CISA KEV catalog (CISA Advisory, Github Advisory).
Users of lwIP should update to a version of the library newer than 2.2.1 by pulling from the official repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git, specifically applying commit f873b6295933e4149a2132adf3e9a2d2a676a5ec which contains the fix. If immediate patching is not feasible, CISA recommends implementing network segmentation to restrict adjacent network access to systems running vulnerable lwIP versions, placing control system networks behind firewalls, and using VPNs for any required remote access. Additionally, minimize network exposure for all affected control system devices and ensure they are not accessible from the internet (CISA Advisory, Github Advisory).
CISA issued ICS Advisory ICSA-26-265-02 on September 22, 2026, highlighting the vulnerability's relevance across multiple critical infrastructure sectors worldwide. Red Hat opened a Bugzilla tracking entry (Bug 2538918) to assess impact on their products. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (CISA Advisory, Red Hat Bugzilla).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."