Fedora 34.x — End of Life
EOL High riskFedora 34.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 34 | Apr 27, 2021 | — | Jun 7, 2022 | 34 | EOL |
CVEs affecting Fedora 34.x (15)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29145 | HIGH | 7.5 | 4.80% | — | 34 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-29117 | HIGH | 7.5 | 4.91% | — | 34 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-27406 | HIGH | 7.5 | 3.39% | — | 34 | FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2022-27405 | HIGH | 7.5 | 2.82% | — | 34 | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 50.84% | — | 34 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2022-0778 | HIGH | 7.5 | 70.56% | — | 34 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n… | Mar 15, 2022 |
| CVE-2022-24512 | MEDIUM | 6.3 | 1.55% | — | 34 | .NET and Visual Studio Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-24464 | HIGH | 7.5 | 3.31% | — | 34 | .NET and Visual Studio Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2022-21293 | MEDIUM | 5.3 | 8.35% | — | 34 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).… | Jan 19, 2022 |
| CVE-2022-21291 | MEDIUM | 5.3 | 2.90% | — | 34 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S… | Jan 19, 2022 |
| CVE-2022-21283 | MEDIUM | 5.3 | 3.78% | — | 34 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).… | Jan 19, 2022 |
| CVE-2021-44832 | MEDIUM | 6.6 | 97.91% | — | 34 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r… | Dec 28, 2021 |
| CVE-2021-4019 | HIGH | 7.8 | 1.79% | — | 34 | vim is vulnerable to Heap-based Buffer Overflow | Dec 1, 2021 |
| CVE-2021-35556 | MEDIUM | 5.3 | 7.88% | — | 34 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported … | Oct 20, 2021 |
| CVE-2021-41617 | HIGH | 7.0 | 2.54% | — | 34 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio… | Sep 26, 2021 |
Fedora 34.x is EOL — migrate to Fedora 35.x
Fedora 35.x is the next major release. Plan your upgrade before Fedora 34.x stops receiving security patches.
Frequently asked questions
Is Fedora 34 end of life?
Yes. All Fedora 34.x releases have reached end of life and no longer receive security patches. There are 15 known CVEs affecting Fedora 34.x. Migrate to Fedora 35.x as soon as possible.
What CVEs affect Fedora 34?
There are 15 CVEs tracked for Fedora 34.x. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 34 version?
The latest Fedora 34.x patch release is 34, released on April 27, 2021. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 34 to Fedora 35?
To migrate from Fedora 34 to Fedora 35: (1) review the official Fedora 35 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 34 in production?
No. Fedora 34 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
