{"id":"CVE-2026-54582","summary":"mport package installation can overwrite existing unmanaged or differently owned files","details":"mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport-\u003eforce. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.","aliases":["GHSA-5773-7r4r-rpgx"],"modified":"2026-09-19T08:08:50.558630Z","published":"2026-09-17T16:50:40.434Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-668","CWE-73"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54582.json"},"references":[{"type":"WEB","url":"https://github.com/MidnightBSD/mport/releases/tag/2.7.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54582.json"},{"type":"ADVISORY","url":"https://github.com/MidnightBSD/mport/security/advisories/GHSA-5773-7r4r-rpgx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54582"},{"type":"FIX","url":"https://github.com/MidnightBSD/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39"},{"type":"FIX","url":"https://github.com/MidnightBSD/mport/pull/131"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/midnightbsd/mport","events":[{"introduced":"0"},{"fixed":"c643312d149dcc994957dbafa8f6f6b61e945e39"},{"fixed":"899c8fe2d3ceb25d899e70dbd0c7744b7d7a0946"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.7.8"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.6","2.7.5","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0","2.6.8","2.6.7","2.6.5","2.6.4","2.6.3","2.6.2","2.6.1","2.6.0","2.5.1","2.5.0","2.4.8","2.4.7","2.4.6","2.4.5","2.4.4","2.4.3","2.4.1","2.4.0","2.3.0","2.2.9.1","2.2.9","2.2.8","2.2.7","2.2.6","2.2.5","2.2.4","2.2.3","2.2.2","2.2.1","2.2.0","2.1.9","2.1.8","2.1.7","2.1.6","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.2","2.0.1","2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54582.json","vanir_signatures_modified":"2026-09-19T08:08:50Z","vanir_signatures":[{"source":"https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39","target":{"file":"libmport/check_preconditions.c"},"deprecated":false,"digest":{"line_hashes":["139998409072723526304835808431628882293","4919190785314921128893676901754589616","225190141764806958041420475193532163293","43221180498533511559009137736180479067","258878559525900125351512404612343010295","90179817598388106023541699532378033312","315085482597379716804606298740316392175","39241207875587401884036599899938370326","40700928156062485872159780795785778738","290251323188867738984007979752365113192"],"threshold":0.9},"id":"CVE-2026-54582-2606eb83","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-54582-3719457f","signature_type":"Function","signature_version":"v1","source":"https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39","target":{"file":"libmport/install_primative.c","function":"mport_install_primative"},"deprecated":false,"digest":{"function_hash":"210565787678153645181664926853993600237","length":4970}},{"digest":{"function_hash":"37640987083385704189634136766023198980","length":809},"id":"CVE-2026-54582-b734d983","signature_type":"Function","signature_version":"v1","source":"https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39","target":{"file":"libmport/check_preconditions.c","function":"mport_check_preconditions"},"deprecated":false},{"digest":{"line_hashes":["116678812365137535500603057149254344138","311977597159923772282748898832063825877","327276169282603603252804954349103709246","131122486032139895278773912104303599000"],"threshold":0.9},"id":"CVE-2026-54582-cba2c950","signature_type":"Line","signature_version":"v1","source":"https://github.com/midnightbsd/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39","target":{"file":"libmport/install_primative.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"}]}