PT-2026-95013 · Midnightbsd · Mport
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
The MidnightBSD Package Manager fails to treat all truncated, corrupt, or failed zstd streams as fatal within the
mport decompress zstd() function. Additionally, the libmport/fetch.c component does not consistently propagate these failures to index-fetch callers. A malicious or faulty mirror could provide compressed package index data that causes ZSTD decompressStream() or an output write to fail, leaving partial index output available. This can lead to package-index integrity loss or a denial of service.Recommendations
Update to version 2.7.8.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport