Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot traversal or substitute symlinks during privileged package installation, causing directory creation or attribute changes to affect attacker-selected paths outside the intended package directories. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Insecure directory manipulation during privileged package installation may allow a local attacker to create or modify files outside the intended package scope, enabling privilege escalation or system compromise.
Action: Patch
AI Analysis

Impact

mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets—identified as ASSET_DIR or ASSET_DIR_OWNER_MODE—could be created or owned during package installation by calling path‑based mport_mkdirp() along with ownership and permission changes. A local attacker with write access to part of the target installation tree can cause a race between path traversal attempts (using ..) and the creation of symlinks. This race allows the attacker to dictate that the operating system creates directories or changes attributes outside of the intended package directories. The result is that files can be placed in arbitrary locations that the installer will later populate, thereby potentially granting the attacker additional privileges or enabling the modification of system components. The impact is an escalation of privileges or unauthorized file system modifications that occur under the guise of a legitimate package installation.

Affected Systems

This vulnerability affects MidnightBSD systems that run the mport package manager. Any installation of mport earlier than version 2.7.8 is susceptible. The issue arises when manipulating directory assets during package installation, as handled by libmport/bundle_read_install_pkg.c.

Risk and Exploitability

The listed CVSS score of 5.8 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be locally privileged or able to write to the package installation tree, and the attacker must initiate a package installation that processes the affected asset directories. The race condition exploited is a classic resource‑synchronization flaw (CWE‑367), combined with path traversal (CWE‑59).

Generated by OpenCVE AI on September 19, 2026 at 03:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install mport version 2.7.8 or later to apply the official fix.
  • Restrict write access to the directories that mport uses for package installation, ensuring that only trusted users can modify them while installations run.
  • Implement filesystem integrity monitoring to detect unexpected directory changes during package installation.

Generated by OpenCVE AI on September 19, 2026 at 03:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot traversal or substitute symlinks during privileged package installation, causing directory creation or attribute changes to affect attacker-selected paths outside the intended package directories. This issue is fixed in version 2.7.8.
Title mport directory asset installation is vulnerable to symlink and path traversal races
Weaknesses CWE-367
CWE-59
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:15:12.857Z

Reserved: 2026-06-15T19:15:27.345Z

Link: CVE-2026-54587

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:04.931Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:44.020

Modified: 2026-09-17T21:15:06.427

Link: CVE-2026-54587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')