mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-668",
"CWE-73"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54582.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54582.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"139998409072723526304835808431628882293",
"4919190785314921128893676901754589616",
"225190141764806958041420475193532163293",
"43221180498533511559009137736180479067",
"258878559525900125351512404612343010295",
"90179817598388106023541699532378033312",
"315085482597379716804606298740316392175",
"39241207875587401884036599899938370326",
"40700928156062485872159780795785778738",
"290251323188867738984007979752365113192"
],
"threshold": 0.9
},
"id": "CVE-2026-54582-2606eb83",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39",
"target": {
"file": "libmport/check_preconditions.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "210565787678153645181664926853993600237",
"length": 4970
},
"id": "CVE-2026-54582-3719457f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39",
"target": {
"file": "libmport/install_primative.c",
"function": "mport_install_primative"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "37640987083385704189634136766023198980",
"length": 809
},
"id": "CVE-2026-54582-b734d983",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39",
"target": {
"file": "libmport/check_preconditions.c",
"function": "mport_check_preconditions"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"116678812365137535500603057149254344138",
"311977597159923772282748898832063825877",
"327276169282603603252804954349103709246",
"131122486032139895278773912104303599000"
],
"threshold": 0.9
},
"id": "CVE-2026-54582-cba2c950",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39",
"target": {
"file": "libmport/install_primative.c"
}
}
]
"2026-09-19T08:08:50Z"