Fedora 35.x — End of Life
EOL Actively exploitedFedora 35.x reached end of life on Dec 13, 2022, 1394 days ago, and no longer receives security fixes. The most recent release in this series is 35. 55 CVEs are tracked for this series, including 6 critical and 5 actively exploited according to CISA KEV. The next major version is Fedora 36. See Fedora 36 →
Fedora 35.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 35 | Nov 2, 2021 | — | Dec 13, 2022 | 35 | EOL |
CVEs affecting Fedora 35.x (55)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-39399 | LOW | 3.7 | 1.64% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)… | Oct 18, 2022 |
| CVE-2022-21626 | MEDIUM | 5.3 | 1.94% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). … | Oct 18, 2022 |
| CVE-2022-21624 | LOW | 3.7 | 1.57% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp… | Oct 18, 2022 |
| CVE-2022-21619 | LOW | 3.7 | 2.66% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). … | Oct 18, 2022 |
| CVE-2022-21618 | MEDIUM | 5.3 | 2.27% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supp… | Oct 18, 2022 |
| CVE-2022-3324 | HIGH | 7.8 | 0.53% | — | 35 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | Sep 27, 2022 |
| CVE-2022-3297 | HIGH | 7.8 | 0.52% | — | 35 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | Sep 25, 2022 |
| CVE-2022-3296 | HIGH | 7.8 | 0.56% | — | 35 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | Sep 25, 2022 |
| CVE-2022-3256 | HIGH | 7.8 | 0.48% | — | 35 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | Sep 22, 2022 |
| CVE-2022-38178 | HIGH | 7.5 | 2.98% | — | 35 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-38177 | HIGH | 7.5 | 3.15% | — | 35 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-2795 | MEDIUM | 5.3 | 2.19% | — | 35 | By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe… | Sep 21, 2022 |
| CVE-2022-38013 | HIGH | 7.5 | 4.03% | — | 35 | .NET Core and Visual Studio Denial of Service Vulnerability | Sep 13, 2022 |
| CVE-2022-3037 | HIGH | 7.8 | 0.52% | — | 35 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | Aug 30, 2022 |
| CVE-2022-37434 | CRITICAL | 9.8 | 18.97% | — | 35 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header… | Aug 5, 2022 |
| CVE-2021-41556 | CRITICAL | 10.0 | 2.75% | — | 35 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca… | Jul 28, 2022 |
| CVE-2022-2294 | HIGH | 8.8 | 70.46% | KEV | 35 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit… | Jul 28, 2022 |
| CVE-2022-2160 | MEDIUM | 6.5 | 0.67% | — | 35 | Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who c… | Jul 28, 2022 |
| CVE-2022-21549 | MEDIUM | 5.3 | 2.52% | — | 35 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).… | Jul 19, 2022 |
| CVE-2022-34169 | HIGH | 7.5 | 81.75% | — | 35 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee… | Jul 19, 2022 |
| CVE-2022-29145 | HIGH | 7.5 | 5.43% | — | 35 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-29117 | HIGH | 7.5 | 5.68% | — | 35 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-29968 | HIGH | 7.8 | 1.05% | — | 35 | An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kio… | May 2, 2022 |
| CVE-2022-27406 | HIGH | 7.5 | 3.32% | — | 35 | FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2022-27405 | HIGH | 7.5 | 2.82% | — | 35 | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2022-1055 | HIGH | 7.8 | 0.50% | — | 35 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escala… | Mar 29, 2022 |
| CVE-2022-0995 | HIGH | 7.8 | 8.78% | KEV | 35 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This … | Mar 25, 2022 |
| CVE-2022-0330 | HIGH | 7.8 | 0.38% | — | 35 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r… | Mar 25, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 51.73% | — | 35 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2022-27666 | HIGH | 7.8 | 5.52% | — | 35 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw… | Mar 23, 2022 |
| CVE-2022-1011 | HIGH | 7.8 | 1.16% | — | 35 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allo… | Mar 18, 2022 |
| CVE-2022-24512 | MEDIUM | 6.3 | 1.60% | — | 35 | .NET and Visual Studio Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-24464 | HIGH | 7.5 | 3.55% | — | 35 | .NET and Visual Studio Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2022-26490 | HIGH | 7.8 | 0.43% | — | 35 | st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTIO… | Mar 6, 2022 |
| CVE-2022-0492 | HIGH | 7.8 | 5.52% | KEV | 35 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th… | Mar 3, 2022 |
| CVE-2022-23304 | CRITICAL | 9.8 | 1.91% | — | 35 | The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel atta… | Jan 17, 2022 |
| CVE-2022-23303 | CRITICAL | 9.8 | 3.05% | — | 35 | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks … | Jan 17, 2022 |
| CVE-2021-44832 | MEDIUM | 6.6 | 97.90% | — | 35 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r… | Dec 28, 2021 |
| CVE-2021-44733 | HIGH | 7.0 | 0.70% | — | 35 | A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs b… | Dec 22, 2021 |
| CVE-2021-4104 | HIGH | 7.5 | 80.59% | — | 35 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Lo… | Dec 14, 2021 |
| CVE-2021-44228 | CRITICAL | 10.0 | 99.99% | KEV | 35 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con… | Dec 10, 2021 |
| CVE-2021-4019 | HIGH | 7.8 | 1.92% | — | 35 | vim is vulnerable to Heap-based Buffer Overflow | Dec 1, 2021 |
| CVE-2021-41184 | MEDIUM | 6.5 | 40.76% | — | 35 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option… | Oct 26, 2021 |
| CVE-2021-41183 | MEDIUM | 6.5 | 8.53% | — | 35 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`… | Oct 26, 2021 |
| CVE-2021-41182 | MEDIUM | 6.5 | 39.36% | — | 35 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` … | Oct 26, 2021 |
| CVE-2021-35556 | MEDIUM | 5.3 | 8.46% | — | 35 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported … | Oct 20, 2021 |
| CVE-2021-41864 | HIGH | 7.8 | 0.41% | — | 35 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri… | Oct 2, 2021 |
| CVE-2021-41617 | HIGH | 7.0 | 2.54% | — | 35 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio… | Sep 26, 2021 |
| CVE-2021-40438 | CRITICAL | 9.0 | 99.99% | KEV | 35 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th… | Sep 16, 2021 |
| CVE-2021-35267 | HIGH | 7.8 | 0.48% | — | 35 | NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror all… | Sep 7, 2021 |
| CVE-2021-35266 | HIGH | 7.8 | 0.48% | — | 35 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer… | Sep 7, 2021 |
| CVE-2021-33287 | HIGH | 7.8 | 0.41% | — | 35 | In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a he… | Sep 7, 2021 |
| CVE-2021-35269 | HIGH | 7.8 | 0.47% | — | 35 | NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_se… | Sep 7, 2021 |
| CVE-2021-35268 | HIGH | 7.8 | 0.47% | — | 35 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a h… | Sep 7, 2021 |
| CVE-2021-33289 | HIGH | 7.8 | 0.48% | — | 35 | In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflo… | Sep 7, 2021 |
Fedora 35.x is EOL — migrate to Fedora 36.x
Fedora 36.x is the next major release. Plan your upgrade before Fedora 35.x stops receiving security patches.
Add a Fedora 35 EOL badge to your README
Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/fedora/35)Frequently asked questions
Is Fedora 35 end of life?
Yes. All Fedora 35.x releases have reached end of life and no longer receive security patches. There are 55 known CVEs affecting Fedora 35.x, including 6 critical. Migrate to Fedora 36.x as soon as possible.
What CVEs affect Fedora 35?
There are 55 CVEs tracked for Fedora 35.x, including 6 critical severity issues and 5 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 35 version?
The latest Fedora 35.x patch release is 35, released on November 2, 2021. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 35 to Fedora 36?
To migrate from Fedora 35 to Fedora 36: (1) review the official Fedora 36 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 35 in production?
No. Fedora 35 has reached end of life and security vulnerabilities are no longer patched. Critically, 5 CVEs affecting Fedora 35.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
