Junglewise Threat Intelligence

CVE-2026-54579: MidnightBSD mport insufficient ICMP reply validation

CVE-2026-54579 · Severity: info · CVSS 5.9 · Published 2026-09-17

Technologies: MidnightBSD Mport. Vendors: MidnightBSD.

Executive brief

mport is the package manager for MidnightBSD, a FreeBSD derivative, and is used to install and manage software on MidnightBSD systems. A flaw in its mirror-selection logic accepts spoofed ICMP replies without proper validation, allowing an attacker to influence which software repository the system trusts, or potentially crash the mirror-selection process with malformed packets.

Technical details

The ping() function in libmport/ping.c prior to version 2.7.8 fails to validate the icmp_id and icmp_seq fields of incoming ICMP replies and incorrectly parses the ICMP header using a fixed IP header offset instead of respecting the actual IP header length (ip_hl). This results in two vulnerability classes: CWE-345 (insufficient verification of data authenticity) and CWE-125 (out-of-bounds read). An attacker on the network with the ability to inject or spoof visible ICMP replies can influence mirror latency selection, causing mport to favor an attacker-controlled mirror. Additionally, malformed ICMP packets carrying IP options can shift the ICMP header location and trigger out-of-bounds memory reads. The fix is available in version 2.7.8, which validates both icmp_id and icmp_seq, uses the correct IP header length, adds timeout handling, and improves resource cleanup.

Affected products

  • MidnightBSD mport before 2.7.8

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: patched: version 2.7.8 released

References

Related threats