Fedora 31.x — End of Life

EOL Actively exploited
EOL: Nov 24, 20201 release in this series15 CVEs

Fedora 31.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
31Oct 29, 2019Nov 24, 202031EOL

CVEs affecting Fedora 31.x (15)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2020-8619MEDIUM4.92.10%31In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi…Jun 17, 2020
CVE-2020-9484HIGH7.056.63%31When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)…May 20, 2020
CVE-2020-10932MEDIUM4.70.25%31An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough s…Apr 15, 2020
CVE-2020-9281MEDIUM6.14.30%31A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke…Mar 7, 2020
CVE-2020-1938CRITICAL9.899.27% KEV 31When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc…Feb 24, 2020
CVE-2019-11050MEDIUM4.87.62%31When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7…Dec 23, 2019
CVE-2019-11049MEDIUM6.54.21%31In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak…Dec 23, 2019
CVE-2019-11046LOW3.74.08%31In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ…Dec 23, 2019
CVE-2019-11045LOW3.78.81%31In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb…Dec 23, 2019
CVE-2019-11044LOW3.75.12%31In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with …Dec 23, 2019
CVE-2019-11135MEDIUM6.53.13%31TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potenti…Nov 14, 2019
CVE-2019-16910MEDIUM5.31.77%31Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff…Sep 26, 2019
CVE-2019-10086HIGH7.329.95%31In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for a…Aug 20, 2019
CVE-2019-13118MEDIUM5.35.18%31In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an in…Jul 1, 2019
CVE-2019-13117MEDIUM5.36.45%31In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb…Jul 1, 2019

Fedora 31.x is EOL — migrate to Fedora 32.x

Fedora 32.x is the next major release. Plan your upgrade before Fedora 31.x stops receiving security patches.

See Fedora 32.x

Frequently asked questions

Is Fedora 31 end of life?

Yes. All Fedora 31.x releases have reached end of life and no longer receive security patches. There are 15 known CVEs affecting Fedora 31.x, including 1 critical. Migrate to Fedora 32.x as soon as possible.

What CVEs affect Fedora 31?

There are 15 CVEs tracked for Fedora 31.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 31 version?

The latest Fedora 31.x patch release is 31, released on October 29, 2019. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 31 to Fedora 32?

To migrate from Fedora 31 to Fedora 32: (1) review the official Fedora 32 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 31 in production?

No. Fedora 31 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 31.x is in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA