mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the conditions that make hashing fail could receive a misleading integrity result or hide a checksum failure. This issue is fixed in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-354",
"CWE-755"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54578.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54578.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "48574886222134429902133642127475821908",
"length": 2508
},
"id": "CVE-2026-54578-45e3a48e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
"target": {
"file": "libmport/verify.c",
"function": "mport_recompute_checksums"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "220838471745406615829116593924094538339",
"length": 2147
},
"id": "CVE-2026-54578-7c9945cb",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
"target": {
"file": "libmport/verify.c",
"function": "mport_verify_package"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"329687312515367208881458425530073892634",
"141727976096257026439559858096397637774",
"321109419376040539584577892658036146184",
"171617735145170586663261593464930266402",
"255239139954349029560404795770474487690",
"14833606681747582872969611709899135935",
"207901533427395719996082642874170430553",
"55290917468561257710431161601683483380",
"17714715188604884069970172288818028614",
"331744096772012592438517186245069213740",
"256324952856976219795552176890598302944",
"202931507511567966296234461992319819098",
"17621729333046449469155390804836764321",
"12121565095560539579093651461696883589",
"36534069261954404670030564118081344761",
"148869562514968579839068379707199128296",
"24017107848818770892524387227673781330",
"161906934790450731428914171971324387917",
"271310293295668405256805460776655115707",
"220866739051721231871445461933122185505",
"146815062087845910256894805100052153217",
"200350414813323654684679966324357858393",
"256324952856976219795552176890598302944",
"202931507511567966296234461992319819098",
"17621729333046449469155390804836764321",
"12121565095560539579093651461696883589",
"36534069261954404670030564118081344761",
"219892870414467845467569877511343702323",
"211930322288711281262042088571172080154",
"13113358575243448095588077414679139537",
"257535432932558301314644327842462248844",
"261014184013114151755327115610686919605",
"307127448862444570411417075682458059174",
"149044743174864078188547851372420456204",
"329687312515367208881458425530073892634",
"141727976096257026439559858096397637774",
"321109419376040539584577892658036146184",
"194553842462738189194081264495737847765",
"98287066717145427211893234683667243308",
"304124350362753225285351773285695263812",
"9003481255295730291833630367415482825",
"284586601332763836378494600477906295440",
"252876413123244673862385244489301628023",
"309278092586140014654690392970445271856",
"222036071836150543787499141276899056422",
"119839765357746062496655771790023035988",
"104682045600100745903496275143014880492",
"141673790135788574364393533208030002120",
"31289928615246404780618384388026767280",
"193920678679347733093669254343717480122",
"83293108543333040387506693613515431178",
"83125882061956465448098756184955740197",
"154227748730180703916681130318217066344"
],
"threshold": 0.9
},
"id": "CVE-2026-54578-c31e4dad",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
"target": {
"file": "libmport/verify.c"
}
}
]
"2026-09-20T14:24:13Z"