| Type: | BUG |
| Impact: | NA |
| Release Date: | 2026-09-03 |
[1.3.9d-2]
- Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293)
[1.3.9d-1]
- Update to 1.3.9d
- SSH channel open request from authenticated client with max packet size of
zero lead to infinite loop (GH#2242)
- Aborted/failed data transfers incorrectly clear any 'EPSV ALL' state
(GH#2255)
- Possible use-after-free issue via FTP STAT command using -C option; note
that the -C option is now silently ignored for FTP STAT commands (GH#2265)
- Passive FTP data transfers do not honor AllowForeignAddress policy properly
(GH#2272)
- Empty password fields should be rejected by the mod_sql_passwd module
(GH#2275)
- Empty password fields should be rejected by the mod_auth_file module
(GH#2279)
- .ftpaccess file policy bypass possible in certain configurations (GH#2282)
[1.3.9c-4]
- Update mod_procfs to 0.3
- Also block access to sysfs filesystems
[1.3.9c-3]
- Add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via
/proc/self/root path prefix); this module disallows file accesses via procfs
filesystems
[1.3.9c-1]
- Update to 1.3.9c
- ExecEnviron values not passed due to regression since 1.3.8.d (GH#2135)
- Stack buffer overflow in MLSD/MLST handling for long path names (GH#2146)
- MaxTransfersPerUser no longer enforces configured limits (GH#2158)
- AdminControlsACLs for config, get actions not honored as they should be
(GH#2163)
- Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed
buffers without bounds checking (GH#2166)
- RewriteMap unescape builtin use causes one-byte out-of-bounds write, fails
to reject illegal characters (GH#2173)
- SQL group name lookup concatenates client-provided group names without
escaping (GH#2188)
- Authenticated SFTP sessions can overflow the SFTP packet buffer
(GH#2190, CVE-2026-63090)
- Default Controls socket ACLs unintentionally allow all users access for
sending Controls requests (GH#2210)
- Exercise caution when reading the client-provided file size for SCP
uploads, as it could possibly overflow our size type (CVE-2026-63091)
[1.3.9b-1]
- Update to 1.3.9b
- Fix SQL Injection in mod_wrap2_sql via reverse DNS hostname (GH#2057,
CVE-2026-44331)
- Additional fix for session management with OpenSSL 3.2.x or later, when
using TLSv1.2 or earlier; this complements the fix for GH#1963 (GH#2096)
- Hard quota limits on uploads do not cause SFTP WRITE requests to fail as
expected (GH#2098)
- Fix SSH payload length underflow calculation for ETM/ChaChaPoly algorithms
in mod_sftp (GH#2102)
- SSH packet with empty payload triggered null pointer dereference in
mod_sftp (GH#2104)
- Bad DSA signatures could lead to out-of-bounds read of heap memory in
mod_sftp (GH#2106)
- Mismatched RSA/DSA algorithm signatures could lead to null dereference in
mod_sftp (GH#2108)
- SFTP request payload length underflow calculation in mod_sftp
(GH#2115, CVE-2026-53994)
- Several modules failed to build using OpenSSL 4.0 (GH#2120)
- Update mod_proxy to 0.9.7
- Add a check on the maximum allowed SSH payload (vs. packet) length (GH#291)
- Set the payload_len field before checking its value (GH#292)
- Keep the SSH packet reading code in mod_proxy more in line with what is
done in mod_sftp, for legibility (GH#294)
- Implement support for the OpenSSH-specific ChaChaPoly SSH algorithm
(GH#295, GH#296)
- Correct misspellings noted by codespell (GH#297)
- Use clang-tidy to start polishing the codebase (GH#298)
- Disable the Nagle algorithm by default on our TCP connections to back-end
servers (GH#299)
- Require OpenSSL for building (GH#249, GH#300)
- Documentation fixes
- Implement a limit on the number of EXT_INFO extensions we'll be willing to
accept (GH#303)
- Comparison of expected/provided MAC data should be done in a constant-time
manner
- Support PKCS11-stored private keys
- Implement the 'mlkem768x25519-sha256' and 'sntrup761x25519-sha512'
post-quantum SSH key exchange mechanisms (GH#306)
- Add sanity check for SRV record lengths
- Ensure that the SSH payload length computation, for ETM/ChaChaPoly packets,
does not underflow
- If we detect a bad DSA signature length, properly error out
- Ensure that RSA/DSA signatures match their expected algorithm types, and
avoid null pointer dereferences
- Update to build against OpenSSL 4.x (GH#313)
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
| Oracle Linux 10 (aarch64) | proftpd-1.3.9d-2.el10_2.src.rpm | 2a5cd636106e061d86cf027299a327103b9f0ef74409fa4ba49cb3a879c02fa3 | - | ol10_aarch64_u2_developer_EPEL |
| proftpd-1.3.9d-2.el10_2.aarch64.rpm | 2d2adaf4abb00382ccfdd7db1bf27ca77a5c185912f017351ed56685a7395ce8 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-devel-1.3.9d-2.el10_2.aarch64.rpm | c504e337a5e8ba56ce765a18e82e4319ebcab47cf946cdef7c5714b43dafaf25 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-ldap-1.3.9d-2.el10_2.aarch64.rpm | 88132b51cd2081547ef53cf522c098fe59eff1680e5b3b0c5dcb6cfe739e1193 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-mysql-1.3.9d-2.el10_2.aarch64.rpm | f86bc7837066879fa9e68806a200ce48b9b05414f6f093dbc9778087b17e2be2 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-postgresql-1.3.9d-2.el10_2.aarch64.rpm | 249f8337b31c1158854003afdf30824d52897b3b2685a4aba922dfb5f29e31c9 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-proxy-1.3.9d-2.el10_2.aarch64.rpm | 32e3f78495887bfe2bea7a5f72a04a5f8cc99c217c90f43ff4f5c8b92d0a81a2 | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-sqlite-1.3.9d-2.el10_2.aarch64.rpm | 844570c82bd2ccd5bc287c12baed3f306358cfc0f2261919497ca206c635aa0b | - | ol10_aarch64_u2_developer_EPEL | |
| proftpd-utils-1.3.9d-2.el10_2.aarch64.rpm | e99a7c89974121f366088878ae5027ddcefbd697d8872232acc3d3ccfc683997 | - | ol10_aarch64_u2_developer_EPEL | |
| Oracle Linux 10 (x86_64) | proftpd-1.3.9d-2.el10_2.src.rpm | 2a5cd636106e061d86cf027299a327103b9f0ef74409fa4ba49cb3a879c02fa3 | - | ol10_x86_64_u2_developer_EPEL |
| proftpd-1.3.9d-2.el10_2.x86_64.rpm | aa6e99057a25a5bfee828de2e0d2987aa8f8cda0b76deb410bf7a574dc7d682a | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-devel-1.3.9d-2.el10_2.x86_64.rpm | 0b75b018625f4371db95f0df7d57b1147d2742b502c838a2e3326cd2d143b56b | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-ldap-1.3.9d-2.el10_2.x86_64.rpm | e83d7939d296e5b27e57ee84f63bb1437f20363fc68df2fddadd54838c036008 | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-mysql-1.3.9d-2.el10_2.x86_64.rpm | 029cd942cb1b97ee28ad4e1dc1e5c7095e8b5e2ff9a5ecdd85480c7a022107ef | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-postgresql-1.3.9d-2.el10_2.x86_64.rpm | 4815ac2fae3db50b2bbb98cdd44d700703078d79dbc128c879129b9c85ff2852 | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-proxy-1.3.9d-2.el10_2.x86_64.rpm | d90919b19665d03ccf2638c0ce8944a3b3737e121b6cd3b886f967a8af8a906b | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-sqlite-1.3.9d-2.el10_2.x86_64.rpm | 0a5e9eb89a94310d70da9daee49708c38c690237412f8822fb7efbac1b520019 | - | ol10_x86_64_u2_developer_EPEL | |
| proftpd-utils-1.3.9d-2.el10_2.x86_64.rpm | cd7a9bd876554ab165d06308e221c3d4451cfc0230cad51691a2fc9a1bbfd1ea | - | ol10_x86_64_u2_developer_EPEL | |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team