是 MidnightBSD 的包管理器。在版本 2.7.8 之前,包安装过程中缺少对已存在于磁盘上的非目录资产(如普通文件)的预检查。受影响的逻辑位于 、 和 中,这些代码未应用 检查,因此,经过构造或存在冲突的包可能会覆盖由其他包拥有或未被 管理的文件。该检查仅在操作者显式启用 时被绕过。若未设置该强制覆盖选项,而执行具有特权的安装操作,可能会破坏本地文件系统完整性以及包数据库的一致性。此问题已在版本 2.7.8 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54583 | 8.3 HIGH | mport package bundle downloads allow unsafe destination filenames |
| CVE-2026-54581 | 8.3 HIGH | mport bootstrap index fetch can continue after hash verification failure |
| CVE-2026-54580 | 8.3 HIGH | mport index decompression can leave partial or corrupt index data after zstd failures |
| CVE-2026-54585 | 6.0 MEDIUM | mport sample file handling can write outside the configured root |
| CVE-2026-54586 | 6.0 MEDIUM | mport permits repository and package mirror fetches over insecure transport |
| CVE-2026-54587 | 5.8 MEDIUM | mport directory asset installation is vulnerable to symlink and path traversal races |
| CVE-2026-54576 | 5.8 MEDIUM | mport package installation has symlink TOCTOU in chown and chmod handling |
| CVE-2026-54575 | 5.8 MEDIUM | mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
| CVE-2026-54579 | 2.3 LOW | mport mirror-selection ping accepts insufficiently validated ICMP replies |
| CVE-2026-54577 | 2.0 LOW | mport audit can inspect the wrong package when options are present |
| CVE-2026-54578 | 2.0 LOW | mport verify can compare stale checksum data after hashing failures |
No comments yet