Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed package index data that caused ZSTD_decompressStream() or an output write to fail while leaving partial index output available for later use, resulting in package-index integrity loss or denial of service. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service / Integrity Loss
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the MidnightBSD Package Manager’s handling of compressed package index data. When a Zstandard stream fails or is truncated, the decompression routine in libmport/util.c does not treat the failure as fatal, and the fetch routine in libmport/fetch.c does not reliably propagate the error back to callers. As a result, a malformed or corrupted index file may partially decompress and remain available for future use, compromising the trustworthiness of the package inventory and potentially denying the system the ability to install packages correctly. This flaw corresponds to the weaknesses identified as CWE-354 (Data Loss) and CWE-755 (Statement Incomplete).

Affected Systems

The issue affects MidnightBSD’s mport package manager versions prior to 2.7.8. Specifically, any installation running mport before that release is vulnerable when it retrieves package index data from a mirror that can serve corrupted or tampered compressed data. The fixed version, 2.7.8 and later, includes a fatal error path for failed decompression and proper error propagation.

Risk and Exploitability

The CVSS score of 8.3 classifies the flaw as high severity, while the EPSS score of <1% indicates a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, reflecting its current exposure level. The likely attack vector involves a malicious or compromised mirror that supplies a corrupted ZSTD stream; the attacker does not need to breach the target system directly, but can exploit the trust of the package manager in the integrity of mirror data. Successful exploitation could lead to loss of integrity of the package index and a denial of service for package operations.

Generated by OpenCVE AI on September 19, 2026 at 02:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to mport version 2.7.8 or later, which includes fatal error handling for ZSTD decompression failures.
  • Ensure that mirrors used by the package manager are authenticated and regularly scanned for integrity, and consider configuring strict checksum verification for package index downloads.
  • Monitor system logs for failed index fetch attempts and take defensive action if repeated failures are detected.

Generated by OpenCVE AI on September 19, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed package index data that caused ZSTD_decompressStream() or an output write to fail while leaving partial index output available for later use, resulting in package-index integrity loss or denial of service. This issue is fixed in version 2.7.8.
Title mport index decompression can leave partial or corrupt index data after zstd failures
Weaknesses CWE-354
CWE-755
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:22.459Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54580

cve-icon Vulnrichment

Updated: 2026-09-24T20:49:59.049Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.150

Modified: 2026-09-24T21:17:16.487

Link: CVE-2026-54580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value

  • CWE-755

    Improper Handling of Exceptional Conditions