Integrity Check Vulnerability in MidnightBSD Package Manager
CVE-2026-54578
2LOW
What is CVE-2026-54578?
The MidnightBSD Package Manager contains a notable integrity check vulnerability in its package verification process. Specifically, prior to version 2.7.8, the function mport_verify_package() in libmport/verify.c could erroneously proceed after failures in checksum calculations (MD5File() or SHA256_File()). This flaw allows an attacker to manipulate files or conditions, leading to inaccurate integrity results or obscured checksum failures. Users are encouraged to update to version 2.7.8 or later to address this issue.
Affected Version(s)
mport < 2.7.8
