mport 是 MidnightBSD 的包管理器。在 2.7.8 版本之前,libmport/bundle_read_install_pkg.c 中以 ASSET_DIR 或 ASSET_DIR_OWNER_MODE 方式处理的目录资源,使用的是基于路径的 mport_mkdirp() 函数,并执行所有权和权限操作。如果本地攻击者能够修改目标安装目录树的部分内容,则可在进行特权包安装过程中,利用路径穿越(如“../”)或替换符号链接,使目录创建或属性变更操作影响攻击者指定的、位于预期包目录之外的路径。该问题已在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MidnightBSD | mport | < 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54583 | 8.3 HIGH | mport package bundle downloads allow unsafe destination filenames |
| CVE-2026-54581 | 8.3 HIGH | mport bootstrap index fetch can continue after hash verification failure |
| CVE-2026-54580 | 8.3 HIGH | mport index decompression can leave partial or corrupt index data after zstd failures |
| CVE-2026-54582 | 6.0 MEDIUM | mport package installation can overwrite existing unmanaged or differently owned files |
| CVE-2026-54585 | 6.0 MEDIUM | mport sample file handling can write outside the configured root |
| CVE-2026-54586 | 6.0 MEDIUM | mport permits repository and package mirror fetches over insecure transport |
| CVE-2026-54576 | 5.8 MEDIUM | mport package installation has symlink TOCTOU in chown and chmod handling |
| CVE-2026-54575 | 5.8 MEDIUM | mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
| CVE-2026-54579 | 2.3 LOW | mport mirror-selection ping accepts insufficiently validated ICMP replies |
| CVE-2026-54577 | 2.0 LOW | mport audit can inspect the wrong package when options are present |
| CVE-2026-54578 | 2.0 LOW | mport verify can compare stale checksum data after hashing failures |
No comments yet