Executive brief
mport is the package manager for MidnightBSD, a FreeBSD derivative, and is used to install and manage software on MidnightBSD systems. A flaw in its mirror-selection logic accepts spoofed ICMP replies without proper validation, allowing an attacker to influence which software repository the system trusts, or potentially crash the mirror-selection process with malformed packets.
Technical details
The ping() function in libmport/ping.c prior to version 2.7.8 fails to validate the icmp_id and icmp_seq fields of incoming ICMP replies and incorrectly parses the ICMP header using a fixed IP header offset instead of respecting the actual IP header length (ip_hl). This results in two vulnerability classes: CWE-345 (insufficient verification of data authenticity) and CWE-125 (out-of-bounds read). An attacker on the network with the ability to inject or spoof visible ICMP replies can influence mirror latency selection, causing mport to favor an attacker-controlled mirror. Additionally, malformed ICMP packets carrying IP options can shift the ICMP header location and trigger out-of-bounds memory reads. The fix is available in version 2.7.8, which validates both icmp_id and icmp_seq, uses the correct IP header length, adds timeout handling, and improves resource cleanup.
Affected products
- MidnightBSD mport before 2.7.8
Timeline
- 2026-06-06: disclosed
- 2026-06-06: patched: version 2.7.8 released