{"id":"CVE-2026-54578","summary":"mport verify can compare stale checksum data after hashing failures","details":"mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the conditions that make hashing fail could receive a misleading integrity result or hide a checksum failure. This issue is fixed in version 2.7.8.","aliases":["GHSA-hgmr-9p75-q5cg"],"modified":"2026-09-20T14:24:13.288457Z","published":"2026-09-17T16:54:20.195Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-354","CWE-755"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54578.json"},"references":[{"type":"WEB","url":"https://github.com/MidnightBSD/mport/releases/tag/2.7.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54578.json"},{"type":"ADVISORY","url":"https://github.com/MidnightBSD/mport/security/advisories/GHSA-hgmr-9p75-q5cg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54578"},{"type":"FIX","url":"https://github.com/MidnightBSD/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990"},{"type":"FIX","url":"https://github.com/MidnightBSD/mport/pull/138"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/midnightbsd/mport","events":[{"introduced":"0"},{"fixed":"cd9991c3cc1f60ecb3f378852ad8b5caa820e990"},{"fixed":"899c8fe2d3ceb25d899e70dbd0c7744b7d7a0946"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.7.8"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.6","2.7.5","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0","2.6.8","2.6.7","2.6.5","2.6.4","2.6.3","2.6.2","2.6.1","2.6.0","2.5.1","2.5.0","2.4.8","2.4.7","2.4.6","2.4.5","2.4.4","2.4.3","2.4.1","2.4.0","2.3.0","2.2.9.1","2.2.9","2.2.8","2.2.7","2.2.6","2.2.5","2.2.4","2.2.3","2.2.2","2.2.1","2.2.0","2.1.9","2.1.8","2.1.7","2.1.6","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.2","2.0.1","2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54578.json","vanir_signatures_modified":"2026-09-20T14:24:13Z","vanir_signatures":[{"target":{"file":"libmport/verify.c","function":"mport_recompute_checksums"},"deprecated":false,"digest":{"function_hash":"48574886222134429902133642127475821908","length":2508},"id":"CVE-2026-54578-45e3a48e","signature_type":"Function","signature_version":"v1","source":"https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990"},{"deprecated":false,"digest":{"function_hash":"220838471745406615829116593924094538339","length":2147},"id":"CVE-2026-54578-7c9945cb","signature_type":"Function","signature_version":"v1","source":"https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990","target":{"file":"libmport/verify.c","function":"mport_verify_package"}},{"source":"https://github.com/midnightbsd/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990","target":{"file":"libmport/verify.c"},"deprecated":false,"digest":{"line_hashes":["329687312515367208881458425530073892634","141727976096257026439559858096397637774","321109419376040539584577892658036146184","171617735145170586663261593464930266402","255239139954349029560404795770474487690","14833606681747582872969611709899135935","207901533427395719996082642874170430553","55290917468561257710431161601683483380","17714715188604884069970172288818028614","331744096772012592438517186245069213740","256324952856976219795552176890598302944","202931507511567966296234461992319819098","17621729333046449469155390804836764321","12121565095560539579093651461696883589","36534069261954404670030564118081344761","148869562514968579839068379707199128296","24017107848818770892524387227673781330","161906934790450731428914171971324387917","271310293295668405256805460776655115707","220866739051721231871445461933122185505","146815062087845910256894805100052153217","200350414813323654684679966324357858393","256324952856976219795552176890598302944","202931507511567966296234461992319819098","17621729333046449469155390804836764321","12121565095560539579093651461696883589","36534069261954404670030564118081344761","219892870414467845467569877511343702323","211930322288711281262042088571172080154","13113358575243448095588077414679139537","257535432932558301314644327842462248844","261014184013114151755327115610686919605","307127448862444570411417075682458059174","149044743174864078188547851372420456204","329687312515367208881458425530073892634","141727976096257026439559858096397637774","321109419376040539584577892658036146184","194553842462738189194081264495737847765","98287066717145427211893234683667243308","304124350362753225285351773285695263812","9003481255295730291833630367415482825","284586601332763836378494600477906295440","252876413123244673862385244489301628023","309278092586140014654690392970445271856","222036071836150543787499141276899056422","119839765357746062496655771790023035988","104682045600100745903496275143014880492","141673790135788574364393533208030002120","31289928615246404780618384388026767280","193920678679347733093669254343717480122","83293108543333040387506693613515431178","83125882061956465448098756184955740197","154227748730180703916681130318217066344"],"threshold":0.9},"id":"CVE-2026-54578-c31e4dad","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}