CVE-2026-54584: mport trusts environment-controlled temporary directories in privileged metadata extraction

Published Sep 21, 2026
·
Updated

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.

Affected Software

1 affected component
mport/mport<2.7.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MidnightBSD mport to a version that resolves this vulnerability.

    Fixed in 2.7.8Patch PR 123

Event History

Sep 21, 2026
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running mport before 2.7.8 are exposed when mport is invoked with root, setuid, or setgid privileges and an attacker can control that invocation's environment.

2

What does an attacker need to exploit it?

The attacker needs the ability to set TMPDIR for a privileged mport process. They can then direct package metadata extraction to an attacker-controlled temporary location.

3

Are normal unprivileged mport invocations affected in the same way?

The described risk is specifically tied to privileged mport invocations, including root and setuid/setgid contexts. The provided information does not identify the same privilege boundary impact for unprivileged use.

4

What should be done if upgrading cannot happen immediately?

Do not allow untrusted users or processes to control TMPDIR or the environment of privileged mport invocations. Use a trusted, non-empty temporary-directory setting for those executions.

5

How can I determine whether a system is remediated?

Verify that mport is version 2.7.8 or later. The fix ignores unsafe TMPDIR values in privileged contexts and rejects an empty TMPDIR value.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203