PT-2026-95010 · Midnightbsd · Mport

·

CVE-2026-54576

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager contains a flaw where the do actual install() function in libmport/bundle read install pkg.c utilizes path-based lstat(), chown(), stat(), and chmod() operations during package installation. A local attacker with write access to a target directory can exploit this by replacing a checked file with a symbolic link before privileged ownership or mode changes are applied. This allows the attacker to redirect these changes to an arbitrary path, potentially compromising filesystem integrity or permissions.
Recommendations Update to version 2.7.8.

Exploit

Fix

Time Of Check To Time Of Use

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54576
GHSA-23G3-7FV3-3CCF

Affected Products

Mport