Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path could race path checks and replacement operations to redirect package downloads, cleanup, or install-related side effects outside the intended cache. The affected lifecycle helper paths also used shell-form invocation, increasing command-line interpretation risk during privileged helper execution. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The mport package manager contains a TOCTOU race condition in privileged fetch and cache‑clean operations. When a local attacker has write access to the package cache or staging path, they can exploit the race between path checks and replacement to redirect downloads or cleanup actions outside the intended cache directory. Additionally, the helper modules invoke subshells using shell‑form syntax, creating a command‐line interpretation risk during privileged execution. Combined, these flaws enable a local attacker to execute arbitrary commands with elevated privileges, potentially compromising the entire system.

Affected Systems

The vulnerability exists in MidnightBSD's mport package manager versions prior to 2.7.8. The affected code resides in libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. Updating to mport 2.7.8 or later removes the race condition and shell‑form invocation issues.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker must be local and possess write permissions to the cache or staging directories to trigger the race, after which they can gain elevated privileges. Due to the required local foothold and the presence of a patch, the overall risk is moderate but actionable.

Generated by OpenCVE AI on September 19, 2026 at 02:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update MidnightBSD mport to version 2.7.8 or later to eliminate the TOCTOU race and shell‑form invocation flaws.
  • Restrict write permissions on the mport package cache and staging directories so that only the owner or privileged users can modify them, reducing the chance that a local attacker can influence path resolution.
  • Verify that privileged helper processes no longer invoke shell commands using shell‑form syntax by inspecting the mport source or configuration; if necessary, replace these calls with explicit path execution.

Generated by OpenCVE AI on September 19, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path could race path checks and replacement operations to redirect package downloads, cleanup, or install-related side effects outside the intended cache. The affected lifecycle helper paths also used shell-form invocation, increasing command-line interpretation risk during privileged helper execution. This issue is fixed in version 2.7.8.
Title mport package fetch and clean paths are vulnerable to TOCTOU filesystem races
Weaknesses CWE-367
CWE-78
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:58:45.216Z

Reserved: 2026-06-15T19:15:27.343Z

Link: CVE-2026-54575

cve-icon Vulnrichment

Updated: 2026-09-21T20:58:40.681Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:42.420

Modified: 2026-09-21T21:17:04.700

Link: CVE-2026-54575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')