Fedora 21.x — End of Life

EOL Medium risk
EOL: Dec 1, 20151 release in this series3 CVEs

Fedora 21.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
21Dec 9, 2014Dec 1, 201521EOL

CVEs affecting Fedora 21.x (3)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2015-8036MEDIUM6.82.87%21Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SS…Nov 2, 2015
CVE-2015-5291MEDIUM6.83.63%21Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.…Nov 2, 2015
CVE-2014-3566LOW3.4100.00%21The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which mak…Oct 15, 2014

Fedora 21.x is EOL — migrate to Fedora 22.x

Fedora 22.x is the next major release. Plan your upgrade before Fedora 21.x stops receiving security patches.

See Fedora 22.x

Frequently asked questions

Is Fedora 21 end of life?

Yes. All Fedora 21.x releases have reached end of life and no longer receive security patches. There are 3 known CVEs affecting Fedora 21.x. Migrate to Fedora 22.x as soon as possible.

What CVEs affect Fedora 21?

There are 3 CVEs tracked for Fedora 21.x. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 21 version?

The latest Fedora 21.x patch release is 21, released on December 9, 2014. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 21 to Fedora 22?

To migrate from Fedora 21 to Fedora 22: (1) review the official Fedora 22 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 21 in production?

No. Fedora 21 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA