mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-377",
"CWE-73"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54584.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54584.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"119957359405669945120030440606740727674",
"256165556245632309551915136949878708254",
"74989649815960105708835506530771921140",
"50614597987925468949691210108052772837",
"235708484124317822188039213208353554795",
"22259209027797341990053315092248903864",
"198471845428013664164575852610006057056",
"306880740727173123494435494042408803526",
"115503530811073493255853405450937932669"
],
"threshold": 0.9
},
"id": "CVE-2026-54584-634324d3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/3790fa49a36cb085f48b204ef189fb82bbee621a",
"target": {
"file": "libmport/bundle_read.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "338998570603308789551057811450505152398",
"length": 909
},
"id": "CVE-2026-54584-afe86c4f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/3790fa49a36cb085f48b204ef189fb82bbee621a",
"target": {
"file": "libmport/bundle_read.c",
"function": "mport_bundle_read_extract_metafiles"
}
}
]
"2026-09-25T08:27:30Z"