Fedora 30.x — End of Life
EOL Actively exploitedFedora 30.x reached end of life on May 26, 2020, 2325 days ago, and no longer receives security fixes. The most recent release in this series is 30. 14 CVEs are tracked for this series, including 2 critical and 1 actively exploited according to CISA KEV. The next major version is Fedora 31. See Fedora 31 →
Fedora 30.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 30 | Apr 30, 2019 | — | May 26, 2020 | 30 | EOL |
CVEs affecting Fedora 30.x (14)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-9281 | MEDIUM | 6.1 | 4.30% | — | 30 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke… | Mar 7, 2020 |
| CVE-2020-1938 | CRITICAL | 9.8 | 99.27% | KEV | 30 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc… | Feb 24, 2020 |
| CVE-2020-6851 | HIGH | 7.5 | 5.18% | — | 30 | OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack … | Jan 13, 2020 |
| CVE-2019-11050 | MEDIUM | 4.8 | 7.62% | — | 30 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7… | Dec 23, 2019 |
| CVE-2019-11049 | MEDIUM | 6.5 | 4.21% | — | 30 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak… | Dec 23, 2019 |
| CVE-2019-11046 | LOW | 3.7 | 4.08% | — | 30 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ… | Dec 23, 2019 |
| CVE-2019-11045 | LOW | 3.7 | 8.81% | — | 30 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb… | Dec 23, 2019 |
| CVE-2019-11044 | LOW | 3.7 | 5.12% | — | 30 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with … | Dec 23, 2019 |
| CVE-2019-11135 | MEDIUM | 6.5 | 3.13% | — | 30 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potenti… | Nov 14, 2019 |
| CVE-2019-16910 | MEDIUM | 5.3 | 1.77% | — | 30 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff… | Sep 26, 2019 |
| CVE-2019-16168 | MEDIUM | 6.5 | 4.25% | — | 30 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missin… | Sep 9, 2019 |
| CVE-2019-10086 | HIGH | 7.3 | 28.38% | — | 30 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for a… | Aug 20, 2019 |
| CVE-2019-11068 | CRITICAL | 9.8 | 5.23% | — | 30 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permi… | Apr 10, 2019 |
| CVE-2019-6109 | MEDIUM | 6.8 | 3.80% | — | 30 | An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o… | Jan 31, 2019 |
Fedora 30.x is EOL — migrate to Fedora 31.x
Fedora 31.x is the next major release. Plan your upgrade before Fedora 30.x stops receiving security patches.
Add a Fedora 30 EOL badge to your README
Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/fedora/30)Frequently asked questions
Is Fedora 30 end of life?
Yes. All Fedora 30.x releases have reached end of life and no longer receive security patches. There are 14 known CVEs affecting Fedora 30.x, including 2 critical. Migrate to Fedora 31.x as soon as possible.
What CVEs affect Fedora 30?
There are 14 CVEs tracked for Fedora 30.x, including 2 critical severity issues and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 30 version?
The latest Fedora 30.x patch release is 30, released on April 30, 2019. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 30 to Fedora 31?
To migrate from Fedora 30 to Fedora 31: (1) review the official Fedora 31 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 30 in production?
No. Fedora 30 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 30.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
