Re: Bug#1142348: ITP: proftpd-mod-procfs -- ProFTPD module mod_procfs

Hilmar Preuße <[email protected]> Sat, 18 Jul 2026 15:07:07 +0200
Newsgroups gmane.linux.debian.devel.general
Organization Hilmar Preuße Inc.
Message-ID <d0872104-f2a3-40d3-85b9-b0573ce85425__24688.2369321369$1784380384$gmane$org@web.de>
On 7/18/26 11:49, Bastian Blank wrote:
> On Sat, Jul 18, 2026 at 11:15:56AM +0200, Bastien Roucaries wrote:

Hello,

>> Why does we could not use systemd restriction ?
> 
> And what about all the other api directories, like /dev, /run, /sys?
> 

As explained the module should address the specific CVE-2026-35025, w/o 
changing the proftp core code. As explained in [1] there are other 
methods to limit access to specific file systems.

Hilmar

[1] https://github.com/proftpd/proftpd/issues/2170
-- 
Testmail
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQRKnq6Z0VRDf4bMmAn98EQ6ARgcNAUCalt6ewUDAAAAAAAKCRD98EQ6ARgcNCB/
AP9HdcEfiJmn70GwjtIgVAScUvaxjSyK2OFT1mp/H8P+HQEAiqxSqeL17ISfZX8T13kcOj6MqQnk
YU/kRWwxVP8tTwk=
=iQ39
-----END PGP SIGNATURE-----