Fedora 35.x — End of Life

EOL Actively exploited
EOL: Dec 13, 20221 release in this series32 CVEs

Fedora 35.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
35Nov 2, 2021Dec 13, 202235EOL

CVEs affecting Fedora 35.x (32)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2022-39399LOW3.71.47%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)…Oct 18, 2022
CVE-2022-21626MEDIUM5.31.75%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). …Oct 18, 2022
CVE-2022-21624LOW3.71.40%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp…Oct 18, 2022
CVE-2022-21619LOW3.72.38%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). …Oct 18, 2022
CVE-2022-21618MEDIUM5.32.03%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supp…Oct 18, 2022
CVE-2022-38013HIGH7.53.23%35.NET Core and Visual Studio Denial of Service VulnerabilitySep 13, 2022
CVE-2022-37434CRITICAL9.815.50%35zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header…Aug 5, 2022
CVE-2021-41556CRITICAL10.02.18%35sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca…Jul 28, 2022
CVE-2022-2160MEDIUM6.50.56%35Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who c…Jul 28, 2022
CVE-2022-21549MEDIUM5.32.25%35Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).…Jul 19, 2022
CVE-2022-34169HIGH7.581.04%35The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee…Jul 19, 2022
CVE-2022-29145HIGH7.54.80%35.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-29117HIGH7.54.91%35.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-27406HIGH7.53.39%35FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2022-27405HIGH7.52.82%35FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2018-25032HIGH7.550.84%35zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2022-24512MEDIUM6.31.55%35.NET and Visual Studio Remote Code Execution VulnerabilityMar 9, 2022
CVE-2022-24464HIGH7.53.31%35.NET and Visual Studio Denial of Service VulnerabilityMar 9, 2022
CVE-2022-0492HIGH7.85.53% KEV 35A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th…Mar 3, 2022
CVE-2022-23304CRITICAL9.81.90%35The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel atta…Jan 17, 2022
CVE-2022-23303CRITICAL9.83.05%35The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks …Jan 17, 2022
CVE-2021-44832MEDIUM6.697.91%35Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r…Dec 28, 2021
CVE-2021-4104HIGH7.581.15%35JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Lo…Dec 14, 2021
CVE-2021-4019HIGH7.81.79%35vim is vulnerable to Heap-based Buffer OverflowDec 1, 2021
CVE-2021-35556MEDIUM5.37.88%35Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported …Oct 20, 2021
CVE-2021-41617HIGH7.02.54%35sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio…Sep 26, 2021
CVE-2021-35267HIGH7.80.49%35NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror all…Sep 7, 2021
CVE-2021-35266HIGH7.80.49%35In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer…Sep 7, 2021
CVE-2021-33287HIGH7.80.41%35In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a he…Sep 7, 2021
CVE-2021-35269HIGH7.80.48%35NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_se…Sep 7, 2021
CVE-2021-35268HIGH7.80.47%35In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a h…Sep 7, 2021
CVE-2021-33289HIGH7.80.49%35In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflo…Sep 7, 2021

Fedora 35.x is EOL — migrate to Fedora 36.x

Fedora 36.x is the next major release. Plan your upgrade before Fedora 35.x stops receiving security patches.

See Fedora 36.x

Frequently asked questions

Is Fedora 35 end of life?

Yes. All Fedora 35.x releases have reached end of life and no longer receive security patches. There are 32 known CVEs affecting Fedora 35.x, including 4 critical. Migrate to Fedora 36.x as soon as possible.

What CVEs affect Fedora 35?

There are 32 CVEs tracked for Fedora 35.x, including 4 critical severity issues and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 35 version?

The latest Fedora 35.x patch release is 35, released on November 2, 2021. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 35 to Fedora 36?

To migrate from Fedora 35 to Fedora 36: (1) review the official Fedora 36 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 35 in production?

No. Fedora 35 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 35.x is in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA