CVE-2026-54576

Source
https://cve.org/CVERecord?id=CVE-2026-54576
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54576.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54576
Aliases
  • GHSA-23g3-7fv3-3ccf
Published
2026-09-17T16:58:25Z
Modified
2026-09-20T14:24:13Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
mport package installation has symlink TOCTOU in chown and chmod handling
Details

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-367",
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54576.json"
}
References

Affected packages

Git / github.com/midnightbsd/mport

Affected ranges

Type
GIT
Repo
https://github.com/midnightbsd/mport
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.7.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.0.1
2.0.2
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.2.9.1
2.3.0
2.4.0
2.4.1
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.7
2.6.8
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54576.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "218249815509163218032459674904403672552",
            "length": 11963
        },
        "id": "CVE-2026-54576-3e996056",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/midnightbsd/mport/commit/4676ac05b1056b54a3d38d03ae8a478bf12c9abe",
        "target": {
            "file": "libmport/bundle_read_install_pkg.c",
            "function": "do_actual_install"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "327438491300116125421263405088949727199",
                "153887587083409822053574765665580065671",
                "115576711375208265052316584538942151910",
                "256559013178003434288111675807456685866",
                "6715799118218162061551545365209709238",
                "269602809400348341245507958202369010565",
                "122293790911489019290157349553238493542",
                "178305337370687984582208400661736610846",
                "143472576958307842200028022728749632974",
                "223837546372808518536754391166195845297",
                "336459044693781211564751339005319304510",
                "242355176747342466908798652423688369307",
                "189917544535398869037989823575793536078",
                "141661169322914020405562828911043238883",
                "140364331986208060534412919390787025831",
                "40680346865083274967969716440016890711",
                "127873878144749560954295345246379864735",
                "244546899951194846183778885023099902680",
                "174232656099492768320869290546855822852",
                "83198882140821608642095818645921192901",
                "312683218432019780460281079687548228767",
                "157410733557440017685903941188248996959",
                "226357234141125602928282610963364977378",
                "281556132165215090912597932088686188954",
                "138792737190931311682616264741458268777",
                "235436749179222075301214308405037480913",
                "233414684105333252512182109619563091818",
                "275813147308434750756272593966260364195",
                "167959006453754722834962320058908565162",
                "171175313986874095191569904631007111415",
                "157771596850218837692583126982993440259",
                "181291268053975188840601754246969972761",
                "2506838879827560630395023475287930871",
                "129950381016054035155635558386001745754",
                "339724734719216414811064634515015909326",
                "265070988273112518256813122740786868687",
                "20377293163437674686923556870451406538",
                "122399327226375434667765213038274711677",
                "4327710242223210563220744680772659206",
                "196847256907142197338261468909594063404",
                "172621309068917668440929957949733538297",
                "42842932645656895143330183734672911656",
                "119040192054799240572053317713567699965",
                "80861387324931246081087696194918990669",
                "189772814737004014726192216092299913796",
                "8050775280525291626752029591949054863",
                "260115946137226969448617960913930292858",
                "204228757063364287881449790577317255017",
                "328104220058645872329645246086128495164",
                "132295490680859853818454080928849278618"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54576-4628a007",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/midnightbsd/mport/commit/4676ac05b1056b54a3d38d03ae8a478bf12c9abe",
        "target": {
            "file": "libmport/bundle_read_install_pkg.c"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:24:13Z"