Fedora 31.x — End of Life
EOL Actively exploitedFedora 31.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 31 | Oct 29, 2019 | — | Nov 24, 2020 | 31 | EOL |
CVEs affecting Fedora 31.x (15)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-8619 | MEDIUM | 4.9 | 2.10% | — | 31 | In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi… | Jun 17, 2020 |
| CVE-2020-9484 | HIGH | 7.0 | 56.63% | — | 31 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)… | May 20, 2020 |
| CVE-2020-10932 | MEDIUM | 4.7 | 0.25% | — | 31 | An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough s… | Apr 15, 2020 |
| CVE-2020-9281 | MEDIUM | 6.1 | 4.30% | — | 31 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke… | Mar 7, 2020 |
| CVE-2020-1938 | CRITICAL | 9.8 | 99.27% | KEV | 31 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc… | Feb 24, 2020 |
| CVE-2019-11050 | MEDIUM | 4.8 | 7.62% | — | 31 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7… | Dec 23, 2019 |
| CVE-2019-11049 | MEDIUM | 6.5 | 4.21% | — | 31 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak… | Dec 23, 2019 |
| CVE-2019-11046 | LOW | 3.7 | 4.08% | — | 31 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ… | Dec 23, 2019 |
| CVE-2019-11045 | LOW | 3.7 | 8.81% | — | 31 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb… | Dec 23, 2019 |
| CVE-2019-11044 | LOW | 3.7 | 5.12% | — | 31 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with … | Dec 23, 2019 |
| CVE-2019-11135 | MEDIUM | 6.5 | 3.13% | — | 31 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potenti… | Nov 14, 2019 |
| CVE-2019-16910 | MEDIUM | 5.3 | 1.77% | — | 31 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff… | Sep 26, 2019 |
| CVE-2019-10086 | HIGH | 7.3 | 29.95% | — | 31 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for a… | Aug 20, 2019 |
| CVE-2019-13118 | MEDIUM | 5.3 | 5.18% | — | 31 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an in… | Jul 1, 2019 |
| CVE-2019-13117 | MEDIUM | 5.3 | 6.45% | — | 31 | In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb… | Jul 1, 2019 |
Fedora 31.x is EOL — migrate to Fedora 32.x
Fedora 32.x is the next major release. Plan your upgrade before Fedora 31.x stops receiving security patches.
Frequently asked questions
Is Fedora 31 end of life?
Yes. All Fedora 31.x releases have reached end of life and no longer receive security patches. There are 15 known CVEs affecting Fedora 31.x, including 1 critical. Migrate to Fedora 32.x as soon as possible.
What CVEs affect Fedora 31?
There are 15 CVEs tracked for Fedora 31.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 31 version?
The latest Fedora 31.x patch release is 31, released on October 29, 2019. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 31 to Fedora 32?
To migrate from Fedora 31 to Fedora 32: (1) review the official Fedora 32 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 31 in production?
No. Fedora 31 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 31.x is in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
