Impact
mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets—identified as ASSET_DIR or ASSET_DIR_OWNER_MODE—could be created or owned during package installation by calling path‑based mport_mkdirp() along with ownership and permission changes. A local attacker with write access to part of the target installation tree can cause a race between path traversal attempts (using ..) and the creation of symlinks. This race allows the attacker to dictate that the operating system creates directories or changes attributes outside of the intended package directories. The result is that files can be placed in arbitrary locations that the installer will later populate, thereby potentially granting the attacker additional privileges or enabling the modification of system components. The impact is an escalation of privileges or unauthorized file system modifications that occur under the guise of a legitimate package installation.
Affected Systems
This vulnerability affects MidnightBSD systems that run the mport package manager. Any installation of mport earlier than version 2.7.8 is susceptible. The issue arises when manipulating directory assets during package installation, as handled by libmport/bundle_read_install_pkg.c.
Risk and Exploitability
The listed CVSS score of 5.8 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be locally privileged or able to write to the package installation tree, and the attacker must initiate a package installation that processes the affected asset directories. The race condition exploited is a classic resource‑synchronization flaw (CWE‑367), combined with path traversal (CWE‑59).
OpenCVE Enrichment