Skip to content
Fedora 44 ProFTPD Security Bugfix Advisory 2026

Fedora 44 ProFTPD Security Bugfix Advisory 2026

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

ProFTPD is an enhanced FTP server with a focus toward simplicity, security,

and ease of configuration. It features a very Apache-like configuration

syntax, and a highly customizable server infrastructure, including support for

multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory

This package defaults to the standalone behavior of ProFTPD, but all the

needed scripts to have it run by systemd instead are included.

Current upstream maintenance release, with a handful of potentially security- related bugfixes.

* Mon Aug 24 2026 Paul Howarth - 1.3.9d-2 - Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293) * Tue Aug 18 2026 Paul Howarth - 1.3.9d-1 - Update to 1.3.9d - SSH channel open request from authenticated client with max packet size of zero lead to infinite loop (GH#2242) - Aborted/failed data transfers incorrectly clear any "EPSV ALL" state (GH#2255) - Possible use-after-free issue via FTP STAT command using -C option; note that the -C option is now silently ignored for FTP STAT commands (GH#2265) - Passive FTP data transfers do not honor AllowForeignAddress policy properly (GH#2272) - Empty password fields should be rejected by the mod_sql_passwd module (GH#2275) - Empty password fields should be rejected by the mod_auth_file module (GH#2279) - .ftpaccess file policy bypass possible in certain configurations (GH#2282) * Tue Aug 4 2026 Paul Howarth - 1.3.9c-4 - Update mod_procfs to 0.3 - Also block access to sysfs filesystems

* Mon Aug 24 2026 Paul Howarth - 1.3.9d-2 - Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293) * Tue Aug 18 2026 Paul Howarth - 1.3.9d-1 - Update to 1.3.9d - SSH channel open request from authenticated client with max packet size of zero lead to infinite loop (GH#2242) - Aborted/failed data transfers incorrectly clear any "EPSV ALL" state (GH#2255) - Possible use-after-free issue via FTP STAT command using -C option; note that the -C option is now silently ignored for FTP STAT commands (GH#2265) - Passive FTP data transfers do not honor AllowForeignAddress policy properly (GH#2272) - Empty password fields should be rejected by the mod_sql_passwd module (GH#2275) - Empty password fields should be rejected by the mod_auth_file module (GH#2279) - .ftpaccess file policy bypass possible in certain configurations (GH#2282) * Tue Aug 4 2026 Paul Howarth - 1.3.9c-4 - Update mod_procfs to 0.3 - Also block access to sysfs filesystems

Fedora Update Notification FEDORA-2026-f073efe2f3 2026-09-03 01:21:51.218412+00:00 Name : proftpd Product : Fedora 44 Version : 1.3.9d Release : 2.fc44 URL : Summary : Flexible, stable and highly-configurable FTP server Description : ProFTPD is an enhanced FTP server with a focus toward simplicity, security, and ease of configuration. It features a very Apache-like configuration syntax, and a highly customizable server infrastructure, including support for multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory visibility. This package defaults to the standalone behavior of ProFTPD, but all the needed scripts to have it run by systemd instead are included.

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f073efe2f3' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

CWE Weaknesses (1)

Platforms (3)

Tools (1)