Integrity Check Vulnerability in MidnightBSD Package Manager
CVE-2026-54578

2LOW

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54578?

The MidnightBSD Package Manager contains a notable integrity check vulnerability in its package verification process. Specifically, prior to version 2.7.8, the function mport_verify_package() in libmport/verify.c could erroneously proceed after failures in checksum calculations (MD5File() or SHA256_File()). This flaw allows an attacker to manipulate files or conditions, leading to inaccurate integrity results or obscured checksum failures. Users are encouraged to update to version 2.7.8 or later to address this issue.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.