Fedora 36.x — End of Life
EOL Actively exploitedFedora 36.x reached end of life on May 16, 2023, 1240 days ago, and no longer receives security fixes. The most recent release in this series is 36. 46 CVEs are tracked for this series, including 3 critical and 1 actively exploited according to CISA KEV. The next major version is Fedora 37. See Fedora 37 →
Fedora 36.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 36 | May 10, 2022 | — | May 16, 2023 | 36 | EOL |
CVEs affecting Fedora 36.x (46)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-1175 | MEDIUM | 6.6 | 0.44% | — | 36 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. | Mar 4, 2023 |
| CVE-2023-1170 | MEDIUM | 6.6 | 0.49% | — | 36 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | Mar 3, 2023 |
| CVE-2023-0433 | HIGH | 7.8 | 0.51% | — | 36 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | Jan 21, 2023 |
| CVE-2023-0288 | HIGH | 7.8 | 0.48% | — | 36 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. | Jan 13, 2023 |
| CVE-2023-0049 | HIGH | 7.8 | 0.56% | — | 36 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | Jan 4, 2023 |
| CVE-2022-46393 | CRITICAL | 9.8 | 1.21% | — | 36 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow … | Dec 15, 2022 |
| CVE-2022-46392 | MEDIUM | 5.3 | 0.82% | — | 36 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough infor… | Dec 15, 2022 |
| CVE-2022-4141 | HIGH | 7.8 | 0.44% | — | 36 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in … | Nov 25, 2022 |
| CVE-2022-38023 | HIGH | 8.1 | 2.35% | — | 36 | Netlogon RPC Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37967 | HIGH | 7.2 | 4.13% | — | 36 | Windows Kerberos Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37966 | HIGH | 8.1 | 2.51% | — | 36 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-39399 | LOW | 3.7 | 1.64% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)… | Oct 18, 2022 |
| CVE-2022-21626 | MEDIUM | 5.3 | 1.94% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). … | Oct 18, 2022 |
| CVE-2022-21624 | LOW | 3.7 | 1.57% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp… | Oct 18, 2022 |
| CVE-2022-21619 | LOW | 3.7 | 2.66% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). … | Oct 18, 2022 |
| CVE-2022-21618 | MEDIUM | 5.3 | 2.27% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supp… | Oct 18, 2022 |
| CVE-2022-3324 | HIGH | 7.8 | 0.53% | — | 36 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | Sep 27, 2022 |
| CVE-2022-3297 | HIGH | 7.8 | 0.52% | — | 36 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | Sep 25, 2022 |
| CVE-2022-3296 | HIGH | 7.8 | 0.56% | — | 36 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | Sep 25, 2022 |
| CVE-2022-3256 | HIGH | 7.8 | 0.48% | — | 36 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | Sep 22, 2022 |
| CVE-2022-38178 | HIGH | 7.5 | 2.98% | — | 36 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-38177 | HIGH | 7.5 | 3.15% | — | 36 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-2795 | MEDIUM | 5.3 | 2.19% | — | 36 | By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe… | Sep 21, 2022 |
| CVE-2022-38013 | HIGH | 7.5 | 4.03% | — | 36 | .NET Core and Visual Studio Denial of Service Vulnerability | Sep 13, 2022 |
| CVE-2022-3037 | HIGH | 7.8 | 0.52% | — | 36 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | Aug 30, 2022 |
| CVE-2022-37434 | CRITICAL | 9.8 | 18.97% | — | 36 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header… | Aug 5, 2022 |
| CVE-2021-41556 | CRITICAL | 10.0 | 2.75% | — | 36 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca… | Jul 28, 2022 |
| CVE-2022-2294 | HIGH | 8.8 | 70.46% | KEV | 36 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit… | Jul 28, 2022 |
| CVE-2022-2160 | MEDIUM | 6.5 | 0.67% | — | 36 | Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who c… | Jul 28, 2022 |
| CVE-2022-21549 | MEDIUM | 5.3 | 2.52% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).… | Jul 19, 2022 |
| CVE-2022-21540 | MEDIUM | 5.3 | 4.16% | — | 36 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S… | Jul 19, 2022 |
| CVE-2022-34169 | HIGH | 7.5 | 81.75% | — | 36 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee… | Jul 19, 2022 |
| CVE-2022-29145 | HIGH | 7.5 | 5.43% | — | 36 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-29117 | HIGH | 7.5 | 5.68% | — | 36 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-29968 | HIGH | 7.8 | 1.05% | — | 36 | An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kio… | May 2, 2022 |
| CVE-2022-27406 | HIGH | 7.5 | 3.32% | — | 36 | FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2022-27405 | HIGH | 7.5 | 2.82% | — | 36 | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func… | Apr 22, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 51.73% | — | 36 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2022-0778 | HIGH | 7.5 | 73.18% | — | 36 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n… | Mar 15, 2022 |
| CVE-2022-24512 | MEDIUM | 6.3 | 1.60% | — | 36 | .NET and Visual Studio Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-24464 | HIGH | 7.5 | 3.55% | — | 36 | .NET and Visual Studio Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2021-45450 | HIGH | 7.5 | 1.18% | — | 36 | In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or ora… | Dec 21, 2021 |
| CVE-2021-41164 | HIGH | 8.2 | 1.34% | — | 36 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advance… | Nov 17, 2021 |
| CVE-2021-41184 | MEDIUM | 6.5 | 40.76% | — | 36 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option… | Oct 26, 2021 |
| CVE-2021-41183 | MEDIUM | 6.5 | 8.53% | — | 36 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`… | Oct 26, 2021 |
| CVE-2021-41182 | MEDIUM | 6.5 | 39.36% | — | 36 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` … | Oct 26, 2021 |
Fedora 36.x is EOL — migrate to Fedora 37.x
Fedora 37.x is the next major release. Plan your upgrade before Fedora 36.x stops receiving security patches.
Add a Fedora 36 EOL badge to your README
Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/fedora/36)Frequently asked questions
Is Fedora 36 end of life?
Yes. All Fedora 36.x releases have reached end of life and no longer receive security patches. There are 46 known CVEs affecting Fedora 36.x, including 3 critical. Migrate to Fedora 37.x as soon as possible.
What CVEs affect Fedora 36?
There are 46 CVEs tracked for Fedora 36.x, including 3 critical severity issues and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 36 version?
The latest Fedora 36.x patch release is 36, released on May 10, 2022. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 36 to Fedora 37?
To migrate from Fedora 36 to Fedora 37: (1) review the official Fedora 37 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 36 in production?
No. Fedora 36 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 36.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
