CVE-2026-54578

Source
https://cve.org/CVERecord?id=CVE-2026-54578
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54578.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54578
Aliases
  • GHSA-hgmr-9p75-q5cg
Published
2026-09-17T16:54:20Z
Modified
2026-09-20T14:24:13Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
mport verify can compare stale checksum data after hashing failures
Details

mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the conditions that make hashing fail could receive a misleading integrity result or hide a checksum failure. This issue is fixed in version 2.7.8.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-354",
        "CWE-755"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54578.json"
}
References

Affected packages

Git / github.com/midnightbsd/mport

Affected ranges

Type
GIT
Repo
https://github.com/midnightbsd/mport
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.7.8"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0
2.0.1
2.0.2
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.2.9.1
2.3.0
2.4.0
2.4.1
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.7
2.6.8
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54578.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "48574886222134429902133642127475821908",
            "length":  2508
        },
        "id":  "CVE-2026-54578-45e3a48e",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
        "target":  {
            "file":  "libmport/verify.c",
            "function":  "mport_recompute_checksums"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "220838471745406615829116593924094538339",
            "length":  2147
        },
        "id":  "CVE-2026-54578-7c9945cb",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
        "target":  {
            "file":  "libmport/verify.c",
            "function":  "mport_verify_package"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "329687312515367208881458425530073892634",
                "141727976096257026439559858096397637774",
                "321109419376040539584577892658036146184",
                "171617735145170586663261593464930266402",
                "255239139954349029560404795770474487690",
                "14833606681747582872969611709899135935",
                "207901533427395719996082642874170430553",
                "55290917468561257710431161601683483380",
                "17714715188604884069970172288818028614",
                "331744096772012592438517186245069213740",
                "256324952856976219795552176890598302944",
                "202931507511567966296234461992319819098",
                "17621729333046449469155390804836764321",
                "12121565095560539579093651461696883589",
                "36534069261954404670030564118081344761",
                "148869562514968579839068379707199128296",
                "24017107848818770892524387227673781330",
                "161906934790450731428914171971324387917",
                "271310293295668405256805460776655115707",
                "220866739051721231871445461933122185505",
                "146815062087845910256894805100052153217",
                "200350414813323654684679966324357858393",
                "256324952856976219795552176890598302944",
                "202931507511567966296234461992319819098",
                "17621729333046449469155390804836764321",
                "12121565095560539579093651461696883589",
                "36534069261954404670030564118081344761",
                "219892870414467845467569877511343702323",
                "211930322288711281262042088571172080154",
                "13113358575243448095588077414679139537",
                "257535432932558301314644327842462248844",
                "261014184013114151755327115610686919605",
                "307127448862444570411417075682458059174",
                "149044743174864078188547851372420456204",
                "329687312515367208881458425530073892634",
                "141727976096257026439559858096397637774",
                "321109419376040539584577892658036146184",
                "194553842462738189194081264495737847765",
                "98287066717145427211893234683667243308",
                "304124350362753225285351773285695263812",
                "9003481255295730291833630367415482825",
                "284586601332763836378494600477906295440",
                "252876413123244673862385244489301628023",
                "309278092586140014654690392970445271856",
                "222036071836150543787499141276899056422",
                "119839765357746062496655771790023035988",
                "104682045600100745903496275143014880492",
                "141673790135788574364393533208030002120",
                "31289928615246404780618384388026767280",
                "193920678679347733093669254343717480122",
                "83293108543333040387506693613515431178",
                "83125882061956465448098756184955740197",
                "154227748730180703916681130318217066344"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-54578-c31e4dad",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
        "target":  {
            "file":  "libmport/verify.c"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:24:13Z"