Impact
The vulnerability resides in the MidnightBSD Package Manager’s handling of compressed package index data. When a Zstandard stream fails or is truncated, the decompression routine in libmport/util.c does not treat the failure as fatal, and the fetch routine in libmport/fetch.c does not reliably propagate the error back to callers. As a result, a malformed or corrupted index file may partially decompress and remain available for future use, compromising the trustworthiness of the package inventory and potentially denying the system the ability to install packages correctly. This flaw corresponds to the weaknesses identified as CWE-354 (Data Loss) and CWE-755 (Statement Incomplete).
Affected Systems
The issue affects MidnightBSD’s mport package manager versions prior to 2.7.8. Specifically, any installation running mport before that release is vulnerable when it retrieves package index data from a mirror that can serve corrupted or tampered compressed data. The fixed version, 2.7.8 and later, includes a fatal error path for failed decompression and proper error propagation.
Risk and Exploitability
The CVSS score of 8.3 classifies the flaw as high severity, while the EPSS score of <1% indicates a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, reflecting its current exposure level. The likely attack vector involves a malicious or compromised mirror that supplies a corrupted ZSTD stream; the attacker does not need to breach the target system directly, but can exploit the trust of the package manager in the integrity of mirror data. Successful exploitation could lead to loss of integrity of the package index and a denial of service for package operations.
OpenCVE Enrichment