mport 是 MidnightBSD 的包管理器。在 2.7.8 版本之前, 中的 函数在 或 哈希计算失败后,可能会继续执行后续逻辑,并使用哈希缓冲区中残留的旧数据与预期校验值进行比较,而不是使用新计算出的摘要。能够影响已安装文件内容或导致哈希计算失败的外部攻击者,可能会获得具有误导性的完整性验证结果,或者掩盖校验失败的实际情况。该问题已在 2.7.8 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54583 | 8.3 HIGH | mport package bundle downloads allow unsafe destination filenames |
| CVE-2026-54581 | 8.3 HIGH | mport bootstrap index fetch can continue after hash verification failure |
| CVE-2026-54580 | 8.3 HIGH | mport index decompression can leave partial or corrupt index data after zstd failures |
| CVE-2026-54582 | 6.0 MEDIUM | mport package installation can overwrite existing unmanaged or differently owned files |
| CVE-2026-54585 | 6.0 MEDIUM | mport sample file handling can write outside the configured root |
| CVE-2026-54586 | 6.0 MEDIUM | mport permits repository and package mirror fetches over insecure transport |
| CVE-2026-54587 | 5.8 MEDIUM | mport directory asset installation is vulnerable to symlink and path traversal races |
| CVE-2026-54576 | 5.8 MEDIUM | mport package installation has symlink TOCTOU in chown and chmod handling |
| CVE-2026-54575 | 5.8 MEDIUM | mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
| CVE-2026-54579 | 2.3 LOW | mport mirror-selection ping accepts insufficiently validated ICMP replies |
| CVE-2026-54577 | 2.0 LOW | mport audit can inspect the wrong package when options are present |
No comments yet