Fedora 38.x — End of Life

EOL Actively exploited
EOL: May 21, 20241 release in this series25 CVEs

Fedora 38.x reached end of life on May 21, 2024, 869 days ago, and no longer receives security fixes. The most recent release in this series is 38. 25 CVEs are tracked for this series, including 2 actively exploited according to CISA KEV. The next major version is Fedora 39. See Fedora 39 →

Fedora 38.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
38Apr 18, 2023—May 21, 202438EOL

CVEs affecting Fedora 38.x (25)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2024-27019HIGH7.80.21%—38In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __…May 1, 2024
CVE-2024-27018HIGH8.20.63%—38In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook …May 1, 2024
CVE-2024-27017HIGH7.80.29%—38In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view o…May 1, 2024
CVE-2024-27016HIGH7.10.33%—38In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure…May 1, 2024
CVE-2024-27012MEDIUM5.50.27%—38In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when del…May 1, 2024
CVE-2024-26994HIGH7.80.29%—38In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a c…May 1, 2024
CVE-2024-22373HIGH8.11.65%—38An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater…Apr 25, 2024
CVE-2024-26922HIGH7.80.31%—38In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o…Apr 23, 2024
CVE-2024-28960HIGH8.20.84%—38An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C…Mar 29, 2024
CVE-2024-22049MEDIUM5.31.29%—38httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated a…Jan 4, 2024
CVE-2023-48706LOW3.60.54%—38Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` com…Nov 22, 2023
CVE-2023-39999MEDIUM4.31.04%—38Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, …Oct 13, 2023
CVE-2023-5535HIGH7.80.51%—38Use After Free in GitHub repository vim/vim prior to v9.0.2010.Oct 11, 2023
CVE-2023-44487HIGH7.599.99% KEV 38The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many…Oct 10, 2023
CVE-2023-43615HIGH7.50.78%—38Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.Oct 7, 2023
CVE-2023-4806MEDIUM5.91.60%—38A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has…Sep 18, 2023
CVE-2023-4752HIGH7.80.56%—38Use After Free in GitHub repository vim/vim prior to 9.0.1858.Sep 4, 2023
CVE-2023-4750HIGH7.80.53%—38Use After Free in GitHub repository vim/vim prior to 9.0.1857.Sep 4, 2023
CVE-2023-4733HIGH7.80.54%—38Use After Free in GitHub repository vim/vim prior to 9.0.1840.Sep 4, 2023
CVE-2023-38180HIGH7.514.01% KEV 38.NET and Visual Studio Denial of Service VulnerabilityAug 8, 2023
CVE-2023-36664HIGH7.83.85%—38Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | p…Jun 25, 2023
CVE-2023-2426MEDIUM5.30.40%—38Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.Apr 29, 2023
CVE-2023-1175MEDIUM6.60.44%—38Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.Mar 4, 2023
CVE-2023-1170MEDIUM6.60.49%—38Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.Mar 3, 2023
CVE-2023-25136MEDIUM6.589.68%—38OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i…Feb 3, 2023

Fedora 38.x is EOL — migrate to Fedora 39.x

Fedora 39.x is the next major release. Plan your upgrade before Fedora 38.x stops receiving security patches.

See Fedora 39.x

Add a Fedora 38 EOL badge to your README

Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Fedora 38 EOL status
[![Fedora 38 EOL status](https://eolcanary.com/badge/fedora/38.svg)](https://eolcanary.com/explore/fedora/38)

Frequently asked questions

Is Fedora 38 end of life?

Yes. All Fedora 38.x releases have reached end of life and no longer receive security patches. There are 25 known CVEs affecting Fedora 38.x. Migrate to Fedora 39.x as soon as possible.

What CVEs affect Fedora 38?

There are 25 CVEs tracked for Fedora 38.x and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 38 version?

The latest Fedora 38.x patch release is 38, released on April 18, 2023. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 38 to Fedora 39?

To migrate from Fedora 38 to Fedora 39: (1) review the official Fedora 39 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 38 in production?

No. Fedora 38 has reached end of life and security vulnerabilities are no longer patched. Critically, 2 CVEs affecting Fedora 38.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA