PT-2026-95013 · Midnightbsd · Mport

·

CVE-2026-54580

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager fails to treat all truncated, corrupt, or failed zstd streams as fatal within the mport decompress zstd() function. Additionally, the libmport/fetch.c component does not consistently propagate these failures to index-fetch callers. A malicious or faulty mirror could provide compressed package index data that causes ZSTD decompressStream() or an output write to fail, leaving partial index output available. This can lead to package-index integrity loss or a denial of service.
Recommendations Update to version 2.7.8.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54580
GHSA-FFQJ-J42R-747W

Affected Products

Mport