Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Integrity compromise leading to potential remote code execution via malicious bootstrap packages
Action: Immediate Patch
AI Analysis

Impact

The mport_fetch_bootstrap_index() function in MidnightBSD’s mport package manager allowed the command to return success even when hash verification of the bootstrap index failed. This flaw enabled an attacker capable of altering the bootstrap index or its transport path to provide an unverified or tampered index, thereby allowing the installation of malicious packages during system bootstrapping. The vulnerability can thus lead to a compromise of the integrity of the entire system if malicious code is injected through the bootstrap process.

Affected Systems

The vulnerability affects MidnightBSD mport versions prior to 2.7.8. It is resolved in release 2.7.8. Only the MidnightBSD package manager is impacted; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the short term, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector is a network attacker or a compromised mirror that can modify or substitute the bootstrap index. Successful exploitation would require the attacker to supply altered index data that bypasses hash checks, after which mport would continue the bootstrap installation process with that corrupted data, potentially installing compromised packages.

Generated by OpenCVE AI on September 19, 2026 at 02:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MidnightBSD mport to version 2.7.8 or later, which contains the hash verification fix.
  • Configure mport to use only trusted mirror hosts and enforce TLS transport to prevent tampering of the bootstrap index during transit.
  • If bootstrap packages are not required, disable bootstrap installation or restrict to a limited set of signed mirrors to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.
Title mport bootstrap index fetch can continue after hash verification failure
Weaknesses CWE-345
CWE-347
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:17:19.437Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54581

cve-icon Vulnrichment

Updated: 2026-09-17T19:17:12.702Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.290

Modified: 2026-09-17T21:15:06.427

Link: CVE-2026-54581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature