Back

MEDIUM

mport package installation has symlink TOCTOU in chown and chmod handling

Published Sep 17, 2026

Description

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 18, 2026
Reserved Jun 15, 2026
CISA Vulnrichment
Updated Sep 18, 2026
NVD
Status Deferred
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a