mport 是 MidnightBSD 的包管理器。在 2.7.8 版本之前,libmport/fetch.c 中的 mport_fetch_bootstrap_index() 函数在遇到缺失或无效的引导索引哈希值时,可能返回成功,因为其失败路径未保留致命错误状态。因此,能够篡改引导索引内容或其传输路径的网络攻击者或被攻陷的镜像服务器,可能导致 mport 基于未经过验证或已被篡改的引导包索引继续执行。该问题已在 2.7.8 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54583 | 8.3 HIGH | mport package bundle downloads allow unsafe destination filenames |
| CVE-2026-54580 | 8.3 HIGH | mport index decompression can leave partial or corrupt index data after zstd failures |
| CVE-2026-54582 | 6.0 MEDIUM | mport package installation can overwrite existing unmanaged or differently owned files |
| CVE-2026-54585 | 6.0 MEDIUM | mport sample file handling can write outside the configured root |
| CVE-2026-54586 | 6.0 MEDIUM | mport permits repository and package mirror fetches over insecure transport |
| CVE-2026-54587 | 5.8 MEDIUM | mport directory asset installation is vulnerable to symlink and path traversal races |
| CVE-2026-54576 | 5.8 MEDIUM | mport package installation has symlink TOCTOU in chown and chmod handling |
| CVE-2026-54575 | 5.8 MEDIUM | mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
| CVE-2026-54579 | 2.3 LOW | mport mirror-selection ping accepts insufficiently validated ICMP replies |
| CVE-2026-54577 | 2.0 LOW | mport audit can inspect the wrong package when options are present |
| CVE-2026-54578 | 2.0 LOW | mport verify can compare stale checksum data after hashing failures |
No comments yet