Fedora 36.x — End of Life

EOL Critical risk
EOL: May 16, 20231 release in this series23 CVEs

Fedora 36.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
36May 10, 2022May 16, 202336EOL

CVEs affecting Fedora 36.x (23)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2022-46393CRITICAL9.81.15%36An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow …Dec 15, 2022
CVE-2022-46392MEDIUM5.30.79%36An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough infor…Dec 15, 2022
CVE-2022-39399LOW3.71.47%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)…Oct 18, 2022
CVE-2022-21626MEDIUM5.31.75%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). …Oct 18, 2022
CVE-2022-21624LOW3.71.40%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp…Oct 18, 2022
CVE-2022-21619LOW3.72.38%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). …Oct 18, 2022
CVE-2022-21618MEDIUM5.32.03%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supp…Oct 18, 2022
CVE-2022-38013HIGH7.53.23%36.NET Core and Visual Studio Denial of Service VulnerabilitySep 13, 2022
CVE-2022-37434CRITICAL9.815.50%36zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header…Aug 5, 2022
CVE-2021-41556CRITICAL10.02.18%36sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca…Jul 28, 2022
CVE-2022-2160MEDIUM6.50.56%36Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who c…Jul 28, 2022
CVE-2022-21549MEDIUM5.32.25%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).…Jul 19, 2022
CVE-2022-21540MEDIUM5.33.69%36Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S…Jul 19, 2022
CVE-2022-34169HIGH7.581.04%36The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee…Jul 19, 2022
CVE-2022-29145HIGH7.54.80%36.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-29117HIGH7.54.91%36.NET and Visual Studio Denial of Service VulnerabilityMay 10, 2022
CVE-2022-27406HIGH7.53.39%36FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2022-27405HIGH7.52.82%36FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func…Apr 22, 2022
CVE-2018-25032HIGH7.550.84%36zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2022-0778HIGH7.570.56%36The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n…Mar 15, 2022
CVE-2022-24512MEDIUM6.31.55%36.NET and Visual Studio Remote Code Execution VulnerabilityMar 9, 2022
CVE-2022-24464HIGH7.53.31%36.NET and Visual Studio Denial of Service VulnerabilityMar 9, 2022
CVE-2021-45450HIGH7.51.13%36In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or ora…Dec 21, 2021

Fedora 36.x is EOL — migrate to Fedora 37.x

Fedora 37.x is the next major release. Plan your upgrade before Fedora 36.x stops receiving security patches.

See Fedora 37.x

Frequently asked questions

Is Fedora 36 end of life?

Yes. All Fedora 36.x releases have reached end of life and no longer receive security patches. There are 23 known CVEs affecting Fedora 36.x, including 3 critical. Migrate to Fedora 37.x as soon as possible.

What CVEs affect Fedora 36?

There are 23 CVEs tracked for Fedora 36.x, including 3 critical severity issues. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 36 version?

The latest Fedora 36.x patch release is 36, released on May 10, 2022. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 36 to Fedora 37?

To migrate from Fedora 36 to Fedora 37: (1) review the official Fedora 37 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 36 in production?

No. Fedora 36 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA