Executive brief
mport is the package manager for MidnightBSD systems. A flaw in the audit command could cause it to check the wrong target when options are used, resulting in vulnerable packages being incorrectly reported as safe. This could allow administrators to unknowingly deploy systems with unpatched security issues.
Technical details
The vulnerability is a command-line argument parsing bug in mport/mport.c's audit command. When users supplied options like -r before a package name, the function computed adjusted argument values (local_argv, local_argc) but failed to reset optind and optreset state before passing arguments to audit_package(). This caused the function to audit the option token itself rather than the requested package, producing false-negative audit results. The fix (version 2.7.8) properly resets optind and optreset before processing adjusted arguments. No special privileges or network access are required; the bug manifests during normal operator or automated package auditing workflows.
Affected products
- MidnightBSD mport prior to 2.7.8
Timeline
- 2026-05-31: disclosed: Fix merged upstream
- 2026-05-31: patched: Version 2.7.8 released