Back

LOW

mport mirror-selection ping accepts insufficiently validated ICMP replies

Published Sep 17, 2026

Description

mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency selection, while a malformed packet carrying IP options could shift the ICMP header and trigger an out-of-bounds read. This issue is fixed in version 2.7.8.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 24, 2026
Reserved Jun 15, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Deferred
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a