Fedora 34.x — End of Life

EOL Actively exploited
EOL: Jun 7, 20221 release in this series32 CVEs

Fedora 34.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
34Apr 27, 2021Jun 7, 202234EOL

CVEs affecting Fedora 34.x (32)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2022-29145HIGH7.54.94%34.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-29117HIGH7.55.05%34.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-27406HIGH7.53.32%34FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2022-27405HIGH7.52.82%34FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2022-0330HIGH7.80.37%34A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r…Mar 25, 2022
CVE-2018-25032HIGH7.551.73%34zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2022-27666HIGH7.85.52%34A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw…Mar 23, 2022
CVE-2022-1011HIGH7.81.16%34A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allo…Mar 18, 2022
CVE-2022-0778HIGH7.573.18%34The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n…Mar 15, 2022
CVE-2021-3739HIGH7.10.61%34A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, whe…Mar 10, 2022
CVE-2022-24512MEDIUM6.31.60%34.NET and Visual Studio Remote Code Execution VulnerabilityMar 9, 2022
CVE-2022-24464HIGH7.53.55%34.NET and Visual Studio Denial of Service VulnerabilityMar 9, 2022
CVE-2022-26490HIGH7.80.43%34st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTIO…Mar 6, 2022
CVE-2021-20322HIGH7.46.84%34A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functional…Feb 18, 2022
CVE-2022-21293MEDIUM5.38.34%34Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).…Jan 19, 2022
CVE-2022-21291MEDIUM5.32.89%34Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S…Jan 19, 2022
CVE-2022-21283MEDIUM5.33.78%34Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).…Jan 19, 2022
CVE-2021-44832MEDIUM6.697.90%34Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r…Dec 28, 2021
CVE-2021-44228CRITICAL10.099.99% KEV 34Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con…Dec 10, 2021
CVE-2021-4019HIGH7.81.79%34vim is vulnerable to Heap-based Buffer OverflowDec 1, 2021
CVE-2021-41184MEDIUM6.540.76%34jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option…Oct 26, 2021
CVE-2021-41183MEDIUM6.58.53%34jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`…Oct 26, 2021
CVE-2021-41182MEDIUM6.539.36%34jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` …Oct 26, 2021
CVE-2021-35556MEDIUM5.38.46%34Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported …Oct 20, 2021
CVE-2021-41864HIGH7.80.40%34prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri…Oct 2, 2021
CVE-2021-41617HIGH7.02.54%34sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio…Sep 26, 2021
CVE-2021-40438CRITICAL9.099.99% KEV 34A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th…Sep 16, 2021
CVE-2021-40490HIGH7.00.30%34A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux ker…Sep 3, 2021
CVE-2021-38166HIGH7.80.31%34In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when ma…Aug 7, 2021
CVE-2021-33034HIGH7.80.81%34In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5…May 14, 2021
CVE-2021-23134HIGH7.80.37%34Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their pr…May 12, 2021
CVE-2021-23133MEDIUM6.70.47%34A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalatio…Apr 22, 2021

Fedora 34.x is EOL — migrate to Fedora 35.x

Fedora 35.x is the next major release. Plan your upgrade before Fedora 34.x stops receiving security patches.

See Fedora 35.x

Frequently asked questions

Is Fedora 34 end of life?

Yes. All Fedora 34.x releases have reached end of life and no longer receive security patches. There are 32 known CVEs affecting Fedora 34.x, including 2 critical. Migrate to Fedora 35.x as soon as possible.

What CVEs affect Fedora 34?

There are 32 CVEs tracked for Fedora 34.x, including 2 critical severity issues and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 34 version?

The latest Fedora 34.x patch release is 34, released on April 27, 2021. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 34 to Fedora 35?

To migrate from Fedora 34 to Fedora 35: (1) review the official Fedora 35 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 34 in production?

No. Fedora 34 has reached end of life and security vulnerabilities are no longer patched. Critically, 2 CVEs affecting Fedora 34.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA