CVE-2026-91018: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-91018 is a double free vulnerability in lwIP (Lightweight IP), a lightweight TCP/IP stack widely used in embedded and IoT systems. It affects lwIP API versions 2.0.1 through 2.2.1 and was publicly disclosed on September 22, 2026, via a CISA ICS Advisory (ICSA-26-265-02). The vulnerability was reported by Eric Evenchick of Tetrel Security. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (CISA Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-415 (Double Free) and CWE-1341 (Multiple Releases of Same Resource or Handle), occurring when the lwIP stack frees the same memory address twice, leading to heap corruption. An unauthenticated attacker on an adjacent network can trigger this condition without any user interaction or special privileges. The fix is available as a specific commit (f873b6295933e4149a2132adf3e9a2d2a676a5ec) in the official lwIP repository. No detailed public technical write-up or proof-of-concept code has been published as of the disclosure date (CISA Advisory, Github Advisory).

Impact

Successful exploitation can result in a system crash, denial of service (DoS), memory corruption, or arbitrary code execution on the affected system. Given that lwIP is broadly deployed across critical infrastructure sectors — including Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare, Transportation, and Water/Wastewater Systems — the potential blast radius is significant. An attacker achieving code execution could pivot to further compromise embedded or OT/ICS devices on the same network segment (CISA Advisory).

Exploitability

No public proof-of-concept exploit code exists, and no in-the-wild exploitation has been reported as of the disclosure date. CISA explicitly notes that no known public exploitation specifically targeting this vulnerability has been reported, and the vulnerability is not exploitable remotely (requires adjacent network access). The EPSS score is 0.0, reflecting the current absence of observed exploitation activity. The vulnerability has not been added to the CISA KEV catalog (CISA Advisory, Github Advisory).

Mitigation and workarounds

Users of lwIP should update to a version of the library newer than 2.2.1 by pulling from the official repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git, specifically applying commit f873b6295933e4149a2132adf3e9a2d2a676a5ec which contains the fix. If immediate patching is not feasible, CISA recommends implementing network segmentation to restrict adjacent network access to systems running vulnerable lwIP versions, placing control system networks behind firewalls, and using VPNs for any required remote access. Additionally, minimize network exposure for all affected control system devices and ensure they are not accessible from the internet (CISA Advisory, Github Advisory).

Community reactions

CISA issued ICS Advisory ICSA-26-265-02 on September 22, 2026, highlighting the vulnerability's relevance across multiple critical infrastructure sectors worldwide. Red Hat opened a Bugzilla tracking entry (Bug 2538918) to assess impact on their products. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (CISA Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

lwip

Affected

sid

lwip

Affected

trixie

lwip

Affected

Ubuntu

Unknown

devel

lwip

Unknown

focal (esm-apps)

lwip

Unknown

jammy

lwip

Unknown

jammy (esm-apps)

lwip

Unknown

noble

lwip

Unknown

noble (esm-apps)

lwip

Unknown

resolute

lwip

Unknown

resolute (esm-apps)

lwip

Unknown

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91018HIGH8.7
  • Linux Debian logoLinux Debian
  • lwip
NoNoSep 22, 2026
CVE-2026-91777HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NoNoSep 23, 2026
CVE-2026-91776HIGH7.5
  • Linux Debian logoLinux Debian
  • jackson-databind
NoNoSep 23, 2026
CVE-2026-89425HIGH7.5
  • Linux Debian logoLinux Debian
  • pki-ca
NoNoSep 23, 2026
CVE-2026-82331NONEN/A
  • Linux Debian logoLinux Debian
  • buildstream
NoNoSep 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management