Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency selection, while a malformed packet carrying IP options could shift the ICMP header and trigger an out-of-bounds read. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure through out-of-bounds read
Action: Patch
AI Analysis

Impact

The vulnerability lies in the mport package manager's ping implementation, which accepts ICMP replies without checking the icmp_id or icmp_seq fields and uses a hard‑coded IP-header offset instead of reading the actual header length. An attacker capable of injecting or spoofing ICMP replies can manipulate mirror latency selection to favor malicious mirrors, and a crafted packet containing IP options can shift the header alignment, causing an out‑of‑bounds read and the possibility of leaking memory contents. The weakness corresponds to CWE‑125 and CWE‑345.

Affected Systems

MidnightBSD mport package manager versions older than 2.7.8. These versions are affected by the unchecked ICMP reply handling described above.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity, and the EPSS score of <1 % suggests the likelihood of exploitation is very low. The vulnerability is not present in CISA’s KEV catalog, further reducing the risk profile. Exploitation requires a network attacker able to send spoofed or malicious ICMP echo replies that reach the mport process; no privilege escalation, remote code execution, or direct denial‑of‑service tools are required. The impact is limited to potential information disclosure through an out‑of‑bounds read and a degraded ability to select the optimal package mirror.

Generated by OpenCVE AI on September 19, 2026 at 02:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MidnightBSD mport to version 2.7.8 or later to apply the fixed ping handling.
  • Restrict ICMP echo replies from untrusted sources by configuring firewall rules that only allow replies from known mirror IP addresses.
  • Continuously monitor network traffic for anomalous or spoofed ICMP replies and investigate any changes in mirror selection behavior.

Generated by OpenCVE AI on September 19, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency selection, while a malformed packet carrying IP options could shift the ICMP header and trigger an out-of-bounds read. This issue is fixed in version 2.7.8.
Title mport mirror-selection ping accepts insufficiently validated ICMP replies
Weaknesses CWE-125
CWE-345
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.592Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54579

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:00.835Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.000

Modified: 2026-09-24T21:17:16.357

Link: CVE-2026-54579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-345

    Insufficient Verification of Data Authenticity