Impact
The mport package manager’s verification routine, mport_verify_package(), can erroneously continue after a hash calculation fails and compare a supplied checksum with a residual object in the hash buffer. This flaw can lead to a misleading integrity result or allow a checksum failure to go undetected. The weakness is an improper handling of error states in cryptographic functions, reflected by CWE-354 (Incorrect Resource Management) and CWE-755 (Unexpected Error State).
Affected Systems
Any MidnightBSD system running the mport package manager before release 2.7.8 is affected. The vulnerability is present in all earlier versions and resolved in 2.7.8; no specific sub‑version ranges are listed outside this general cutoff.
Risk and Exploitability
The CVSS score of 2 indicates low severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. The most likely attack vector requires the attacker to influence a file on the system or create conditions that trigger a hashing failure, implying the attacker has either local or privileged access. Successful exploitation could allow an attacker to hide a failed checksum or trick the system into accepting a tampered package without detection.
OpenCVE Enrichment