ELBA-2026-602867

ELBA-2026-602867 - proftpd Bug Fix update

Type:BUG
Impact:NA
Release Date:2026-09-03

Description


[1.3.9d-2]
- Fix regression in mod_sql's SQLNamedQuery (upstream bug 4515, GH#2293)

[1.3.9d-1]
- Update to 1.3.9d
- SSH channel open request from authenticated client with max packet size of
zero lead to infinite loop (GH#2242)
- Aborted/failed data transfers incorrectly clear any 'EPSV ALL' state
(GH#2255)
- Possible use-after-free issue via FTP STAT command using -C option; note
that the -C option is now silently ignored for FTP STAT commands (GH#2265)
- Passive FTP data transfers do not honor AllowForeignAddress policy properly
(GH#2272)
- Empty password fields should be rejected by the mod_sql_passwd module
(GH#2275)
- Empty password fields should be rejected by the mod_auth_file module
(GH#2279)
- .ftpaccess file policy bypass possible in certain configurations (GH#2282)

[1.3.9c-4]
- Update mod_procfs to 0.3
- Also block access to sysfs filesystems

[1.3.9c-3]
- Add mod_procfs, enabled by default, to address CVE-2026-35025 (ACL bypass via
/proc/self/root path prefix); this module disallows file accesses via procfs
filesystems

[1.3.9c-1]
- Update to 1.3.9c
- ExecEnviron values not passed due to regression since 1.3.8.d (GH#2135)
- Stack buffer overflow in MLSD/MLST handling for long path names (GH#2146)
- MaxTransfersPerUser no longer enforces configured limits (GH#2158)
- AdminControlsACLs for config, get actions not honored as they should be
(GH#2163)
- Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed
buffers without bounds checking (GH#2166)
- RewriteMap unescape builtin use causes one-byte out-of-bounds write, fails
to reject illegal characters (GH#2173)
- SQL group name lookup concatenates client-provided group names without
escaping (GH#2188)
- Authenticated SFTP sessions can overflow the SFTP packet buffer
(GH#2190, CVE-2026-63090)
- Default Controls socket ACLs unintentionally allow all users access for
sending Controls requests (GH#2210)
- Exercise caution when reading the client-provided file size for SCP
uploads, as it could possibly overflow our size type (CVE-2026-63091)

[1.3.9b-1]
- Update to 1.3.9b
- Fix SQL Injection in mod_wrap2_sql via reverse DNS hostname (GH#2057,
CVE-2026-44331)
- Additional fix for session management with OpenSSL 3.2.x or later, when
using TLSv1.2 or earlier; this complements the fix for GH#1963 (GH#2096)
- Hard quota limits on uploads do not cause SFTP WRITE requests to fail as
expected (GH#2098)
- Fix SSH payload length underflow calculation for ETM/ChaChaPoly algorithms
in mod_sftp (GH#2102)
- SSH packet with empty payload triggered null pointer dereference in
mod_sftp (GH#2104)
- Bad DSA signatures could lead to out-of-bounds read of heap memory in
mod_sftp (GH#2106)
- Mismatched RSA/DSA algorithm signatures could lead to null dereference in
mod_sftp (GH#2108)
- SFTP request payload length underflow calculation in mod_sftp
(GH#2115, CVE-2026-53994)
- Several modules failed to build using OpenSSL 4.0 (GH#2120)
- Update mod_proxy to 0.9.7
- Add a check on the maximum allowed SSH payload (vs. packet) length (GH#291)
- Set the payload_len field before checking its value (GH#292)
- Keep the SSH packet reading code in mod_proxy more in line with what is
done in mod_sftp, for legibility (GH#294)
- Implement support for the OpenSSH-specific ChaChaPoly SSH algorithm
(GH#295, GH#296)
- Correct misspellings noted by codespell (GH#297)
- Use clang-tidy to start polishing the codebase (GH#298)
- Disable the Nagle algorithm by default on our TCP connections to back-end
servers (GH#299)
- Require OpenSSL for building (GH#249, GH#300)
- Documentation fixes
- Implement a limit on the number of EXT_INFO extensions we'll be willing to
accept (GH#303)
- Comparison of expected/provided MAC data should be done in a constant-time
manner
- Support PKCS11-stored private keys
- Implement the 'mlkem768x25519-sha256' and 'sntrup761x25519-sha512'
post-quantum SSH key exchange mechanisms (GH#306)
- Add sanity check for SRV record lengths
- Ensure that the SSH payload length computation, for ETM/ChaChaPoly packets,
does not underflow
- If we detect a bad DSA signature length, properly error out
- Ensure that RSA/DSA signatures match their expected algorithm types, and
avoid null pointer dereferences
- Update to build against OpenSSL 4.x (GH#313)




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (x86_64) proftpd-1.3.9d-2.el10_2.src.rpm2a5cd636106e061d86cf027299a327103b9f0ef74409fa4ba49cb3a879c02fa3-ol10_x86_64_u2_developer_EPEL
proftpd-1.3.9d-2.el10_2.x86_64.rpmaa6e99057a25a5bfee828de2e0d2987aa8f8cda0b76deb410bf7a574dc7d682a-ol10_x86_64_u2_developer_EPEL
proftpd-devel-1.3.9d-2.el10_2.x86_64.rpm0b75b018625f4371db95f0df7d57b1147d2742b502c838a2e3326cd2d143b56b-ol10_x86_64_u2_developer_EPEL
proftpd-ldap-1.3.9d-2.el10_2.x86_64.rpme83d7939d296e5b27e57ee84f63bb1437f20363fc68df2fddadd54838c036008-ol10_x86_64_u2_developer_EPEL
proftpd-mysql-1.3.9d-2.el10_2.x86_64.rpm029cd942cb1b97ee28ad4e1dc1e5c7095e8b5e2ff9a5ecdd85480c7a022107ef-ol10_x86_64_u2_developer_EPEL
proftpd-postgresql-1.3.9d-2.el10_2.x86_64.rpm4815ac2fae3db50b2bbb98cdd44d700703078d79dbc128c879129b9c85ff2852-ol10_x86_64_u2_developer_EPEL
proftpd-proxy-1.3.9d-2.el10_2.x86_64.rpmd90919b19665d03ccf2638c0ce8944a3b3737e121b6cd3b886f967a8af8a906b-ol10_x86_64_u2_developer_EPEL
proftpd-sqlite-1.3.9d-2.el10_2.x86_64.rpm0a5e9eb89a94310d70da9daee49708c38c690237412f8822fb7efbac1b520019-ol10_x86_64_u2_developer_EPEL
proftpd-utils-1.3.9d-2.el10_2.x86_64.rpmcd7a9bd876554ab165d06308e221c3d4451cfc0230cad51691a2fc9a1bbfd1ea-ol10_x86_64_u2_developer_EPEL



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete