Fedora 32.x — End of Life
EOL Actively exploitedFedora 32.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 32 | Apr 28, 2020 | — | May 25, 2021 | 32 | EOL |
CVEs affecting Fedora 32.x (9)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-23133 | MEDIUM | 6.7 | 0.47% | — | 32 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalatio… | Apr 22, 2021 |
| CVE-2020-1971 | MEDIUM | 5.9 | 7.05% | — | 32 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known… | Dec 8, 2020 |
| CVE-2020-25649 | HIGH | 7.5 | 17.81% | — | 32 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allow… | Dec 3, 2020 |
| CVE-2020-28941 | MEDIUM | 5.5 | 0.33% | — | 32 | An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers … | Nov 19, 2020 |
| CVE-2020-8619 | MEDIUM | 4.9 | 2.10% | — | 32 | In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi… | Jun 17, 2020 |
| CVE-2020-9484 | HIGH | 7.0 | 56.63% | — | 32 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)… | May 20, 2020 |
| CVE-2020-10932 | MEDIUM | 4.7 | 0.25% | — | 32 | An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough s… | Apr 15, 2020 |
| CVE-2020-9281 | MEDIUM | 6.1 | 4.30% | — | 32 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke… | Mar 7, 2020 |
| CVE-2020-1938 | CRITICAL | 9.8 | 99.27% | KEV | 32 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc… | Feb 24, 2020 |
Fedora 32.x is EOL — migrate to Fedora 33.x
Fedora 33.x is the next major release. Plan your upgrade before Fedora 32.x stops receiving security patches.
Frequently asked questions
Is Fedora 32 end of life?
Yes. All Fedora 32.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting Fedora 32.x, including 1 critical. Migrate to Fedora 33.x as soon as possible.
What CVEs affect Fedora 32?
There are 9 CVEs tracked for Fedora 32.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 32 version?
The latest Fedora 32.x patch release is 32, released on April 28, 2020. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 32 to Fedora 33?
To migrate from Fedora 32 to Fedora 33: (1) review the official Fedora 33 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 32 in production?
No. Fedora 32 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 32.x is in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
