Fedora 33.x — End of Life

EOL High risk
EOL: Nov 30, 20211 release in this series10 CVEs

Fedora 33.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
33Oct 27, 2020Nov 30, 202133EOL

CVEs affecting Fedora 33.x (10)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2021-35556MEDIUM5.37.88%33Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported …Oct 20, 2021
CVE-2021-41617HIGH7.02.54%33sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio…Sep 26, 2021
CVE-2021-35267HIGH7.80.49%33NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror all…Sep 7, 2021
CVE-2021-35266HIGH7.80.49%33In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer…Sep 7, 2021
CVE-2021-33287HIGH7.80.41%33In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a he…Sep 7, 2021
CVE-2021-35269HIGH7.80.48%33NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_se…Sep 7, 2021
CVE-2021-35268HIGH7.80.47%33In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a h…Sep 7, 2021
CVE-2021-33289HIGH7.80.49%33In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflo…Sep 7, 2021
CVE-2020-1971MEDIUM5.96.97%33The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known…Dec 8, 2020
CVE-2020-28941MEDIUM5.50.33%33An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers …Nov 19, 2020

Fedora 33.x is EOL — migrate to Fedora 34.x

Fedora 34.x is the next major release. Plan your upgrade before Fedora 33.x stops receiving security patches.

See Fedora 34.x

Frequently asked questions

Is Fedora 33 end of life?

Yes. All Fedora 33.x releases have reached end of life and no longer receive security patches. There are 10 known CVEs affecting Fedora 33.x. Migrate to Fedora 34.x as soon as possible.

What CVEs affect Fedora 33?

There are 10 CVEs tracked for Fedora 33.x. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 33 version?

The latest Fedora 33.x patch release is 33, released on October 27, 2020. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 33 to Fedora 34?

To migrate from Fedora 33 to Fedora 34: (1) review the official Fedora 34 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 33 in production?

No. Fedora 33 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA