Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the MidnightBSD package manager, mport. During installation, the function do_actual_install() performed path‑based lstat, chown, stat, and chmod operations on files to set ownership and permissions. A local attacker with write access to a target directory can replace a file that has just been verified with a symlink before the ownership or mode changes are applied. The privileged changes are then redirected through the symlink to an attacker‑chosen path, allowing the attacker to alter the permissions or ownership of arbitrary files on the system. This compromises filesystem integrity and can be used to elevate privileges. The weakness is a time‑of‑check to time‑of‑use race condition and a path traversal flaw (CWE‑367 and CWE‑59).

Affected Systems

The flaw affects installations performed with MidnightBSD mport version 2.7.7 and earlier. The package manager itself is the vulnerable component; any system using the affected mport for package installations is at risk. Version 2.7.8 and later include a fix that removes the race condition by handling ownership and permission changes in a safe order.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity. The EPSS score is below 1 %, indicating a low likelihood of exploitation observed so far. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires local write access to the installation target directory and occurs during privileged package installation, so the attack vector is local.

Generated by OpenCVE AI on September 19, 2026 at 02:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mport to version 2.7.8 or later to eliminate the race condition and path traversal flaw.
  • Remove write permissions for non‑privileged users on the directories used by mport for package installation to prevent local attackers from creating symlinks.
  • Audit installed packages for unintended permission changes to detect potential abuse of the vulnerability.

Generated by OpenCVE AI on September 19, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.
Title mport package installation has symlink TOCTOU in chown and chmod handling
Weaknesses CWE-367
CWE-59
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:44:36.712Z

Reserved: 2026-06-15T19:15:27.343Z

Link: CVE-2026-54576

cve-icon Vulnrichment

Updated: 2026-09-18T14:36:40.798Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:42.570

Modified: 2026-09-18T15:17:09.180

Link: CVE-2026-54576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')