Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the unadjusted argument could cause mport to audit the option token instead of the requested package, producing a false-negative or useless result that could leave a vulnerable package unidentified. The corrected parsing resets optind and optreset before using the adjusted local arguments. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unidentified vulnerable packages due to false-negative audit results
Action: Patch Upgrade
AI Analysis

Impact

The mport audit command mistakenly examined an option token rather than the intended package, causing a false-negative result that could allow a vulnerable package to remain unnoticed; this flaw is rooted in improper argument parsing and stale option state (CWE-20) and insufficient security checks (CWE-693).

Affected Systems

MidnightBSD’s mport package manager before version 2.7.8 is affected, including any installation or automation that passes options such as -r before a package name to the audit command.

Risk and Exploitability

With a CVSS score of 2 and an EPSS score below 1%, and not listed in CISA KEV, the likelihood of exploitation is low; however, an attacker who can influence audit executions could bypass visibility of vulnerabilities, making prompt patching advisable. The vulnerability requires local or scripted command execution, so it is primarily a local or privileged scenario rather than an internet-facing exploit. Insurance against undetected vulnerabilities is best achieved by applying the 2.7.8 fix or later.

Generated by OpenCVE AI on September 19, 2026 at 02:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest mport release (2.7.8 or newer) to correct the argument handling bug.
  • Avoid using audit options such as -r directly before a package name or edit scripts to rearrange arguments until the patch is applied.
  • Verify audit output after package installation or system updates to confirm no false negatives remain.

Generated by OpenCVE AI on September 19, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the unadjusted argument could cause mport to audit the option token instead of the requested package, producing a false-negative or useless result that could leave a vulnerable package unidentified. The corrected parsing resets optind and optreset before using the adjusted local arguments. This issue is fixed in version 2.7.8.
Title mport audit can inspect the wrong package when options are present
Weaknesses CWE-20
CWE-693
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.326Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54577

cve-icon Vulnrichment

Updated: 2026-09-24T20:49:57.577Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:42.710

Modified: 2026-09-24T21:17:16.220

Link: CVE-2026-54577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-693

    Protection Mechanism Failure