Fedora 33.x — End of Life
EOL High riskFedora 33.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 33 | Oct 27, 2020 | — | Nov 30, 2021 | 33 | EOL |
CVEs affecting Fedora 33.x (19)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-41184 | MEDIUM | 6.5 | 40.76% | — | 33 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option… | Oct 26, 2021 |
| CVE-2021-41183 | MEDIUM | 6.5 | 8.53% | — | 33 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`… | Oct 26, 2021 |
| CVE-2021-41182 | MEDIUM | 6.5 | 39.36% | — | 33 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` … | Oct 26, 2021 |
| CVE-2021-35556 | MEDIUM | 5.3 | 8.46% | — | 33 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported … | Oct 20, 2021 |
| CVE-2021-41864 | HIGH | 7.8 | 0.40% | — | 33 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri… | Oct 2, 2021 |
| CVE-2021-41617 | HIGH | 7.0 | 2.54% | — | 33 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio… | Sep 26, 2021 |
| CVE-2021-35267 | HIGH | 7.8 | 0.48% | — | 33 | NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror all… | Sep 7, 2021 |
| CVE-2021-35266 | HIGH | 7.8 | 0.48% | — | 33 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer… | Sep 7, 2021 |
| CVE-2021-33287 | HIGH | 7.8 | 0.41% | — | 33 | In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a he… | Sep 7, 2021 |
| CVE-2021-35269 | HIGH | 7.8 | 0.47% | — | 33 | NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_se… | Sep 7, 2021 |
| CVE-2021-35268 | HIGH | 7.8 | 0.47% | — | 33 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a h… | Sep 7, 2021 |
| CVE-2021-33289 | HIGH | 7.8 | 0.48% | — | 33 | In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflo… | Sep 7, 2021 |
| CVE-2021-40490 | HIGH | 7.0 | 0.30% | — | 33 | A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux ker… | Sep 3, 2021 |
| CVE-2021-38166 | HIGH | 7.8 | 0.31% | — | 33 | In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when ma… | Aug 7, 2021 |
| CVE-2021-23134 | HIGH | 7.8 | 0.37% | — | 33 | Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their pr… | May 12, 2021 |
| CVE-2021-3501 | HIGH | 7.1 | 0.37% | — | 33 | A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to … | May 6, 2021 |
| CVE-2021-23133 | MEDIUM | 6.7 | 0.47% | — | 33 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalatio… | Apr 22, 2021 |
| CVE-2020-1971 | MEDIUM | 5.9 | 7.05% | — | 33 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known… | Dec 8, 2020 |
| CVE-2020-28941 | MEDIUM | 5.5 | 0.33% | — | 33 | An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers … | Nov 19, 2020 |
Fedora 33.x is EOL — migrate to Fedora 34.x
Fedora 34.x is the next major release. Plan your upgrade before Fedora 33.x stops receiving security patches.
Frequently asked questions
Is Fedora 33 end of life?
Yes. All Fedora 33.x releases have reached end of life and no longer receive security patches. There are 19 known CVEs affecting Fedora 33.x. Migrate to Fedora 34.x as soon as possible.
What CVEs affect Fedora 33?
There are 19 CVEs tracked for Fedora 33.x. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 33 version?
The latest Fedora 33.x patch release is 33, released on October 27, 2020. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 33 to Fedora 34?
To migrate from Fedora 33 to Fedora 34: (1) review the official Fedora 34 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 33 in production?
No. Fedora 33 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
