Fedora ProFTPD Update Fixes ACL Bypass Vulnerability CVE-2026-35025

Fedora ProFTPD Update Fixes ACL Bypass Vulnerability CVE-2026-35025

First seen 30 Jul 2026, 05:21 UTC Linuxsecurity 98% similarity 57.9

Article Content

Browse articles
ThreatCluster

Fedora has released an update for ProFTPD addressing CVE-2026-35025, which involves an ACL bypass via the /proc/self/root path prefix. This vulnerability could allow unauthorized file access through procfs filesystems, potentially compromising system security. The update introduces a new module, mod_procfs, which is enabled by default to mitigate this risk. Users are encouraged to audit their Linux privileges to limit potential escalations and damage. The vulnerability was published on June 24, 2026, and affects multiple versions of the ProFTPD server. The update can be installed using the 'dnf' package manager. System administrators should apply the patch promptly to secure their systems against this vulnerability.

Key Points: • Fedora released a patch for ProFTPD addressing CVE-2026-35025. • The vulnerability allows ACL bypass via /proc/self/root, risking unauthorized file access. • System administrators should update using 'dnf' to mitigate potential security risks.

ThreatCluster AI How this analysis works

Timeline

2026-06-24
CVE-2026-35025 published
CVE-2026-35025 details an ACL bypass vulnerability in ProFTPD affecting file access through procfs filesystems.
Linuxsecurity
2026-07-16
ProFTPD version 1.3.9c-2 rebuilt
Fedora Release Engineering rebuilt ProFTPD version 1.3.9c-2 as part of the update process.
Linuxsecurity
2026-07-21
ProFTPD version 1.3.9c-3 released
Paul Howarth released ProFTPD version 1.3.9c-3, adding mod_procfs to address the ACL bypass vulnerability.
Linuxsecurity
2026-07-30
Patch available for ProFTPD ACL bypass
Fedora advises users to apply the latest ProFTPD update to prevent unauthorized file access due to CVE-2026-35025.
Linuxsecurity

Community

Browse all →