Back Linuxsecurity Fedora 44 ProFTPD Security Bugfix Advisory 2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
ProFTPD is an enhanced FTP server with a focus toward simplicity, security,
and ease of configuration. It features a very Apache-like configuration
syntax, and a highly customizable server infrastructure, including support for
multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory
This package defaults to the standalone behavior of ProFTPD, but all the
needed scripts to have it run by systemd instead are included.
Current upstream maintenance release, with a handful of potentially security- related bugfixes.
* Mon Aug 24 2026 Paul Howarth - 1.3.9d-2 - Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293) * Tue Aug 18 2026 Paul Howarth - 1.3.9d-1 - Update to 1.3.9d - SSH channel open request from authenticated client with max packet size of zero lead to infinite loop (GH#2242) - Aborted/failed data transfers incorrectly clear any "EPSV ALL" state (GH#2255) - Possible use-after-free issue via FTP STAT command using -C option; note that the -C option is now silently ignored for FTP STAT commands (GH#2265) - Passive FTP data transfers do not honor AllowForeignAddress policy properly (GH#2272) - Empty password fields should be rejected by the mod_sql_passwd module (GH#2275) - Empty password fields should be rejected by the mod_auth_file module (GH#2279) - .ftpaccess file policy bypass possible in certain configurations (GH#2282) * Tue Aug 4 2026 Paul Howarth - 1.3.9c-4 - Update mod_procfs to 0.3 - Also block access to sysfs filesystems
* Mon Aug 24 2026 Paul Howarth - 1.3.9d-2 - Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293) * Tue Aug 18 2026 Paul Howarth - 1.3.9d-1 - Update to 1.3.9d - SSH channel open request from authenticated client with max packet size of zero lead to infinite loop (GH#2242) - Aborted/failed data transfers incorrectly clear any "EPSV ALL" state (GH#2255) - Possible use-after-free issue via FTP STAT command using -C option; note that the -C option is now silently ignored for FTP STAT commands (GH#2265) - Passive FTP data transfers do not honor AllowForeignAddress policy properly (GH#2272) - Empty password fields should be rejected by the mod_sql_passwd module (GH#2275) - Empty password fields should be rejected by the mod_auth_file module (GH#2279) - .ftpaccess file policy bypass possible in certain configurations (GH#2282) * Tue Aug 4 2026 Paul Howarth - 1.3.9c-4 - Update mod_procfs to 0.3 - Also block access to sysfs filesystems
Fedora Update Notification FEDORA-2026-f073efe2f3 2026-09-03 01:21:51.218412+00:00 Name : proftpd Product : Fedora 44 Version : 1.3.9d Release : 2.fc44 URL : Summary : Flexible, stable and highly-configurable FTP server Description : ProFTPD is an enhanced FTP server with a focus toward simplicity, security, and ease of configuration. It features a very Apache-like configuration syntax, and a highly customizable server infrastructure, including support for multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory visibility. This package defaults to the standalone behavior of ProFTPD, but all the needed scripts to have it run by systemd instead are included.
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f073efe2f3' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
