Fedora ProFTPD Security Updates Address Critical Vulnerabilities

Fedora ProFTPD Security Updates Address Critical Vulnerabilities

First seen 3 Sep 2026, 07:00 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

On September 3, 2026, Fedora released security updates for ProFTPD versions 1.3.9d-2 and 1.3.9d-1, addressing multiple vulnerabilities. These updates affect Fedora 44 and Fedora 43 systems, with issues including infinite loops from SSH channel requests, improper handling of EPSV states, and potential use-after-free vulnerabilities. The updates also fix security-related bugs in SQL modules that could allow unauthorized access. Administrators are urged to apply these updates to mitigate risks associated with FTP services. The vulnerabilities were identified through upstream maintenance releases, and detailed patch notes were provided by Paul Howarth. The updates are critical for maintaining the security of FTP servers running on these Fedora versions.

Key Points: • Fedora 44 and 43 receive critical ProFTPD updates for multiple vulnerabilities. • Key issues include infinite loops and improper handling of FTP commands. • Administrators are urged to apply patches immediately to secure systems.

Timeline

2026-08-18
Update to ProFTPD 1.3.9d
An update was made to ProFTPD 1.3.9d, fixing several critical issues including infinite loops and data transfer errors.
Linuxsecurity
2026-08-24
Regression fix in mod_sql's SQLNamedQuery
A regression affecting SQLNamedQuery was fixed in ProFTPD 1.3.9d-2, addressing upstream bug 4515.
Linuxsecurity
2026-09-03
Fedora 44 ProFTPD update released
Security updates for ProFTPD 1.3.9d-2 were issued, fixing multiple vulnerabilities affecting Fedora 44.
Linuxsecurity
2026-09-03
Fedora 43 ProFTPD update released
ProFTPD 1.3.9d-1 updates were released, addressing critical FTP vulnerabilities for Fedora 43.
Linuxsecurity