Bug#1142348: ITP: proftpd-mod-procfs -- ProFTPD module mod_procfs

Hilmar Preusse <[email protected]> Sat, 18 Jul 2026 11:11:07 +0200
Newsgroups gmane.linux.debian.devel.general
Message-ID <altDK4ch3VIH5S8t__41715.2822412149$1784366014$gmane$org@rasppi3>
Package: wnpp
Severity: wishlist
Owner: Hilmar Preuße <[email protected]>
X-Debbugs-Cc: [email protected]

* Package name    : proftpd-mod-procfs
  Version         : 0.1
  Upstream Contact: TJ Saunders
* URL             : https://github.com/Castaglia/proftpd-mod_procfs
* License         : GPL-2+
  Programming Lang: C
  Description     : ProFTPD module mod_procfs

The mod_procfs module for ProFTPD affects the visibility and use of the
/proc filesystem directory that is commonly available.
The idea is to mitigate CVE-2026-35025 by limiting access to procfs.

Upstream refuses to solve CVE-2026-35025 by doing code changes. Instead
it is suggested to deny access to the /proc file system. This is exactly,
what is done by that module.

I'm a part of the ProFTP team and I intend to maintain the package in
the team.
signature.asc (application/pgp-signature, 358 B)
-----BEGIN PGP SIGNATURE-----

iNUEABYKAH0WIQRKnq6Z0VRDf4bMmAn98EQ6ARgcNAUCaltDKV8UgAAAAAAuAChp
c3N1ZXItZnByQG5vdGF0aW9ucy5vcGVucGdwLmZpZnRoaG9yc2VtYW4ubmV0NEE5
RUFFOTlEMTU0NDM3Rjg2Q0M5ODA5RkRGMDQ0M0EwMTE4MUMzNAAKCRD98EQ6ARgc
NJ2rAQCHfbcuKU4m5AZbmXwma7UIFDnSvUyHI0/aMjq2+Lq/LwEA5CVQ/rHMADbO
sKdhXbh7VsfE2+cWcD1zam1YBbeerwo=
=w1tF
-----END PGP SIGNATURE-----