Back Linuxsecurity Fedora 44 ProFTPD Update Addresses ACL Bypass CVE-2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
ProFTPD is an enhanced FTP server with a focus toward simplicity, security,
and ease of configuration. It features a very Apache-like configuration
syntax, and a highly customizable server infrastructure, including support for
multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory
This package defaults to the standalone behavior of ProFTPD, but all the
needed scripts to have it run by systemd instead are included.
This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.
* Tue Jul 21 2026 Paul Howarth - 1.3.9c-3 - Add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via /proc/self/root path prefix); this module disallows file accesses via procfs filesystems * Thu Jul 16 2026 Fedora Release Engineering - 1.3.9c-2 - Rebuilt for
* Tue Jul 21 2026 Paul Howarth - 1.3.9c-3 - Add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via /proc/self/root path prefix); this module disallows file accesses via procfs filesystems * Thu Jul 16 2026 Fedora Release Engineering - 1.3.9c-2 - Rebuilt for
[ 1 ] Bug #2492208 - CVE-2026-35025 proftpd: ACL bypass via /proc/self/root path prefix in RNFR [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2994824419' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
