Fedora 37.x — End of Life
EOL Actively exploitedFedora 37.x reached end of life on Dec 5, 2023, 1037 days ago, and no longer receives security fixes. The most recent release in this series is 37. 35 CVEs are tracked for this series, including 2 critical and 2 actively exploited according to CISA KEV. The next major version is Fedora 38. See Fedora 38 →
Fedora 37.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 37 | Nov 15, 2022 | — | Dec 5, 2023 | 37 | EOL |
CVEs affecting Fedora 37.x (35)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-39999 | MEDIUM | 4.3 | 1.04% | — | 37 | Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, … | Oct 13, 2023 |
| CVE-2023-5535 | HIGH | 7.8 | 0.51% | — | 37 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. | Oct 11, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 37 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-43615 | HIGH | 7.5 | 0.78% | — | 37 | Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. | Oct 7, 2023 |
| CVE-2023-4806 | MEDIUM | 5.9 | 1.60% | — | 37 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has… | Sep 18, 2023 |
| CVE-2023-4752 | HIGH | 7.8 | 0.56% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | Sep 4, 2023 |
| CVE-2023-4750 | HIGH | 7.8 | 0.53% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | Sep 4, 2023 |
| CVE-2023-4733 | HIGH | 7.8 | 0.54% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | Sep 4, 2023 |
| CVE-2023-38180 | HIGH | 7.5 | 14.01% | KEV | 37 | .NET and Visual Studio Denial of Service Vulnerability | Aug 8, 2023 |
| CVE-2023-36664 | HIGH | 7.8 | 3.85% | — | 37 | Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | p… | Jun 25, 2023 |
| CVE-2023-2426 | MEDIUM | 5.3 | 0.40% | — | 37 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. | Apr 29, 2023 |
| CVE-2023-1175 | MEDIUM | 6.6 | 0.44% | — | 37 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. | Mar 4, 2023 |
| CVE-2023-1170 | MEDIUM | 6.6 | 0.49% | — | 37 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | Mar 3, 2023 |
| CVE-2023-25136 | MEDIUM | 6.5 | 89.68% | — | 37 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i… | Feb 3, 2023 |
| CVE-2023-0433 | HIGH | 7.8 | 0.51% | — | 37 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | Jan 21, 2023 |
| CVE-2023-0049 | HIGH | 7.8 | 0.56% | — | 37 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | Jan 4, 2023 |
| CVE-2022-46393 | CRITICAL | 9.8 | 1.21% | — | 37 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow … | Dec 15, 2022 |
| CVE-2022-46392 | MEDIUM | 5.3 | 0.82% | — | 37 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough infor… | Dec 15, 2022 |
| CVE-2022-2601 | HIGH | 8.6 | 0.51% | — | 37 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when ca… | Dec 14, 2022 |
| CVE-2022-4141 | HIGH | 7.8 | 0.44% | — | 37 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in … | Nov 25, 2022 |
| CVE-2022-38023 | HIGH | 8.1 | 2.35% | — | 37 | Netlogon RPC Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37967 | HIGH | 7.2 | 4.13% | — | 37 | Windows Kerberos Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37966 | HIGH | 8.1 | 2.51% | — | 37 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-3324 | HIGH | 7.8 | 0.53% | — | 37 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | Sep 27, 2022 |
| CVE-2022-3297 | HIGH | 7.8 | 0.52% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | Sep 25, 2022 |
| CVE-2022-3296 | HIGH | 7.8 | 0.56% | — | 37 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | Sep 25, 2022 |
| CVE-2022-3256 | HIGH | 7.8 | 0.48% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | Sep 22, 2022 |
| CVE-2022-38178 | HIGH | 7.5 | 2.98% | — | 37 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-38177 | HIGH | 7.5 | 3.15% | — | 37 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small me… | Sep 21, 2022 |
| CVE-2022-2795 | MEDIUM | 5.3 | 2.19% | — | 37 | By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe… | Sep 21, 2022 |
| CVE-2022-38013 | HIGH | 7.5 | 4.03% | — | 37 | .NET Core and Visual Studio Denial of Service Vulnerability | Sep 13, 2022 |
| CVE-2022-3037 | HIGH | 7.8 | 0.52% | — | 37 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | Aug 30, 2022 |
| CVE-2022-37434 | CRITICAL | 9.8 | 18.97% | — | 37 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header… | Aug 5, 2022 |
| CVE-2021-45450 | HIGH | 7.5 | 1.18% | — | 37 | In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or ora… | Dec 21, 2021 |
| CVE-2021-41164 | HIGH | 8.2 | 1.34% | — | 37 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advance… | Nov 17, 2021 |
Fedora 37.x is EOL — migrate to Fedora 38.x
Fedora 38.x is the next major release. Plan your upgrade before Fedora 37.x stops receiving security patches.
Add a Fedora 37 EOL badge to your README
Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/fedora/37)Frequently asked questions
Is Fedora 37 end of life?
Yes. All Fedora 37.x releases have reached end of life and no longer receive security patches. There are 35 known CVEs affecting Fedora 37.x, including 2 critical. Migrate to Fedora 38.x as soon as possible.
What CVEs affect Fedora 37?
There are 35 CVEs tracked for Fedora 37.x, including 2 critical severity issues and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 37 version?
The latest Fedora 37.x patch release is 37, released on November 15, 2022. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 37 to Fedora 38?
To migrate from Fedora 37 to Fedora 38: (1) review the official Fedora 38 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 37 in production?
No. Fedora 37 has reached end of life and security vulnerabilities are no longer patched. Critically, 2 CVEs affecting Fedora 37.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
