Skip to content
Fedora ProFTPD Update Fixes ACL Bypass Vulnerability CVE-2026-35025

Fedora ProFTPD Update Fixes ACL Bypass Vulnerability CVE-2026-35025

First seen 30 Jul 2026, 05:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • Fedora released a patch for ProFTPD addressing CVE-2026-35025.
  • The vulnerability allows ACL bypass via /proc/self/root, risking unauthorized file access.
  • System administrators should update using 'dnf' to mitigate potential security risks.

Fedora has released an update for ProFTPD addressing CVE-2026-35025, which involves an ACL bypass via the /proc/self/root path prefix. This vulnerability could allow unauthorized file access through procfs filesystems, potentially compromising system security. The update introduces a new module, mod_procfs, which is enabled by default to mitigate this risk. Users are encouraged to audit their Linux privileges to limit potential escalations and damage. The vulnerability was published on June 24, 2026, and affects multiple versions of the ProFTPD server. The update can be installed using the 'dnf' package manager. System administrators should apply the patch promptly to secure their systems against this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2026-06-24
CVE-2026-35025 published
CVE-2026-35025 details an ACL bypass vulnerability in ProFTPD affecting file access through procfs filesystems.
Linuxsecurity
2026-07-16
ProFTPD version 1.3.9c-2 rebuilt
Fedora Release Engineering rebuilt ProFTPD version 1.3.9c-2 as part of the update process.
Linuxsecurity
2026-07-21
ProFTPD version 1.3.9c-3 released
Paul Howarth released ProFTPD version 1.3.9c-3, adding mod_procfs to address the ACL bypass vulnerability.
Linuxsecurity
2026-07-30
Patch available for ProFTPD ACL bypass
Fedora advises users to apply the latest ProFTPD update to prevent unauthorized file access due to CVE-2026-35025.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-35025 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed