Tuesday 21st July 2026
Fedora Project
Updated proftpd (1.3.9c) in F-43, F-44, Rawhide, EPEL-10.2 and EPEL-10 to add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via /proc/self/root path prefix); this module disallows file accesses via procfs filesystems
Local Packages
Updated proftpd (1.3.9c and 1.3.10rc3) to add mod_procfs as per the Fedora version