diff --git a/avro/pom.xml b/avro/pom.xml
index fc5363b6f..1e2fadcf3 100644
--- a/avro/pom.xml
+++ b/avro/pom.xml
@@ -47,7 +47,7 @@ abstractions.
     
       org.apache.avro
       avro
-      1.11.3
+      1.11.4
     
 
     
diff --git a/avro/src/test/java/com/fasterxml/jackson/dataformat/avro/interop/InteropTestBase.java b/avro/src/test/java/com/fasterxml/jackson/dataformat/avro/interop/InteropTestBase.java
index 5fb8635cc..ff9c5665c 100644
--- a/avro/src/test/java/com/fasterxml/jackson/dataformat/avro/interop/InteropTestBase.java
+++ b/avro/src/test/java/com/fasterxml/jackson/dataformat/avro/interop/InteropTestBase.java
@@ -5,6 +5,8 @@
 import java.lang.reflect.Type;
 
 import org.apache.avro.Schema;
+
+import org.junit.Before;
 import org.junit.runner.RunWith;
 import org.junit.runners.Parameterized;
 
@@ -25,6 +27,16 @@ public enum DummyEnum {
         NORTH, SOUTH, EAST, WEST
     }
 
+    // see https://github.com/FasterXML/jackson-dataformats-binary/pull/539 for
+    // explanation (need to allow-list Jackson test packages for Avro 1.11.4+)
+    @Before
+    public void init() {
+        System.setProperty("org.apache.avro.SERIALIZABLE_PACKAGES",
+                "java.lang,java.math,java.io,java.net,org.apache.avro.reflect," +
+                // ^^^ These are default trusted packages by Avro 1.11.4
+                        InteropTestBase.class.getPackage().getName());
+    }
+
     /**
      * Helper method for building a {@link ParameterizedType} for use with roundTrip(Type, Object)
      *
diff --git a/release-notes/VERSION-2.x b/release-notes/VERSION-2.x
index 8bdf46c01..59917b734 100644
--- a/release-notes/VERSION-2.x
+++ b/release-notes/VERSION-2.x
@@ -26,6 +26,7 @@ Active maintainers:
  (fix contributed by Michal F)
 #536: (avro) Add Logical Type support for `java.util.UUID`
  (contributed by Michal F)
+#539: (avro) Upgrade `org.apache.avro:avro` dependency to 1.11.4
 
 2.18.3 (not yet released)
 
@@ -38,7 +39,7 @@ No changes since 2.18.1
 
 2.18.1 (28-Oct-2024)
 
-#518: Should not read past end for CBOR string values
+#518: (cbor) Should not read past end for CBOR string values
  (contributed by Knut W)
 
 2.18.0 (26-Sep-2024)