Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

mport, the MidnightBSD Package Manager, lacked a preflight check for non‑directory assets that existed on disk before version 2.7.8. A malicious or conflicting package could therefore overwrite a file owned by another package or unmanaged by mport, compromising local filesystem integrity and corrupting the package database, which may enable unauthorized manipulation of system files. This behavior represents a CWE‑668 vulnerability, as it permits overwriting files without proper ownership checks, and it also reflects CWE‑73 characteristics, since the package files can reference paths that are not validated, potentially leading to unintended file modification.

Affected Systems

MidnightBSD’s mport package manager, specifically all releases prior to 2.7.8, is affected. The defect resides in libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h within this product.

Risk and Exploitability

The vulnerability scores a CVSS of 6, indicating medium severity, and the EPSS score is less than 1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires local privileged execution of mport and is only possible when the operator does not enable the force flag, so the overall risk remains moderate but unlikely to be observed in the wild.

Generated by OpenCVE AI on September 19, 2026 at 03:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mport to version 2.7.8 or later, which implements the missing preflight file‑conflict check.
  • Avoid using the --force option unless absolutely necessary, and ensure only trusted packages are installed.
  • Verify that the mport installation process applies MPORT_PRECHECK_FILE_CONFLICTS before writing files; if you maintain custom binaries, backport the patch or confirm the logic is present.

Generated by OpenCVE AI on September 19, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.
Title mport package installation can overwrite existing unmanaged or differently owned files
Weaknesses CWE-668
CWE-73
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:15:52.035Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54582

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:46.879Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.440

Modified: 2026-09-17T21:15:06.427

Link: CVE-2026-54582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere

  • CWE-73

    External Control of File Name or Path