PatchSiren

MidnightBSD CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW MidnightBSD CVE published 2026-09-17

CVE-2026-54578

The CVE-2026-54578 vulnerability affects the MidnightBSD Package Manager (mport), specifically in the mport_verify_package() function in libmport/verify.c. An attacker could influence the integrity result of installed files or hide checksum failures. Defenders should verify file integrity and assess exposure in affected systems. The issue is fixed in mport version 2.7.8. This vulnerability has a low CVSS [truncated]

MEDIUM MidnightBSD CVE published 2026-09-17

CVE-2026-54576

A local attacker with write access to a target directory could exploit a vulnerability in mport, the MidnightBSD Package Manager, to compromise filesystem integrity or permissions by replacing a checked file with a symlink before privileged ownership or mode changes were applied. This issue allows attackers to potentially escalate privileges or manipulate system files, emphasizing the need for defenders t [truncated]