#1148822 lwip: CVE-2026-87121 CVE-2026-91018

Package:
src:lwip
Source:
src:lwip
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 05:31:02 UTC
Severity:
normal
Tags:
#1148822#5
Date:
2026-09-24 05:28:21 UTC
From:
To:
Hi,

The following vulnerabilities were published for lwip.

CVE-2026-87121[0]:
| lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write,
| which may allow an attacker to gain full code execution on the
| device.


CVE-2026-91018[1]:
| lwIP (Lightweight IP) has a double free vulnerability, which could
| crash the system, cause a DoS, memory corruption, or allow code
| execution on the victim system.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87121
https://www.cve.org/CVERecord?id=CVE-2026-87121
https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
[1] https://security-tracker.debian.org/tracker/CVE-2026-91018
https://www.cve.org/CVERecord?id=CVE-2026-91018
https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore