Out-of-Bounds Affecting lwip package, versions <2.1.2+dfsg1-4ubuntu0.1~esm1


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
1.02% (59th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2004-LWIP-16781439
  • published18 Jun 2026
  • disclosed18 May 2026

Introduced: 18 May 2026

CVE-2026-8836  (opens in a new tab)
CWE-119  (opens in a new tab)
CWE-121  (opens in a new tab)

How to fix?

Upgrade Ubuntu:20.04 lwip to version 2.1.2+dfsg1-4ubuntu0.1~esm1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream lwip package and not the lwip package as distributed by Ubuntu. See How to fix? for Ubuntu:20.04 relevant fixed versions and status.

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue.

CVSS Base Scores

version 3.1