Fedora 39.x — End of Life

EOL Actively exploited
EOL: Nov 26, 20241 release in this series25 CVEs

Fedora 39.x reached end of life on Nov 26, 2024, 680 days ago, and no longer receives security fixes. The most recent release in this series is 39. 25 CVEs are tracked for this series, including 1 actively exploited according to CISA KEV. The next major version is Fedora 40. See Fedora 40 →

Fedora 39.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
39Nov 7, 2023—Nov 26, 202439EOL

CVEs affecting Fedora 39.x (25)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2024-27401HIGH7.80.29%—39In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into ac…May 14, 2024
CVE-2024-27400HIGH7.80.24%—39In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_t…May 14, 2024
CVE-2024-27398HIGH8.00.82%—39In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_so…May 14, 2024
CVE-2024-27019HIGH7.80.21%—39In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __…May 1, 2024
CVE-2024-27018HIGH8.20.63%—39In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook …May 1, 2024
CVE-2024-27017HIGH7.80.29%—39In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view o…May 1, 2024
CVE-2024-27016HIGH7.10.33%—39In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure…May 1, 2024
CVE-2024-27012MEDIUM5.50.27%—39In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when del…May 1, 2024
CVE-2024-26994HIGH7.80.29%—39In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a c…May 1, 2024
CVE-2024-22373HIGH8.11.65%—39An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater…Apr 25, 2024
CVE-2024-26922HIGH7.80.31%—39In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o…Apr 23, 2024
CVE-2024-28960HIGH8.20.84%—39An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C…Mar 29, 2024
CVE-2024-21626HIGH8.618.92%—39runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and e…Jan 31, 2024
CVE-2024-1086HIGH7.828.05% KEV 39A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr…Jan 31, 2024
CVE-2024-0443MEDIUM5.50.24%—39A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memo…Jan 12, 2024
CVE-2024-22049MEDIUM5.31.29%—39httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated a…Jan 4, 2024
CVE-2023-51767HIGH7.00.66%—39OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) bec…Dec 24, 2023
CVE-2023-6546HIGH7.00.73%—39A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execu…Dec 21, 2023
CVE-2023-48706LOW3.60.54%—39Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` com…Nov 22, 2023
CVE-2023-5535HIGH7.80.51%—39Use After Free in GitHub repository vim/vim prior to v9.0.2010.Oct 11, 2023
CVE-2023-43615HIGH7.50.78%—39Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.Oct 7, 2023
CVE-2023-4806MEDIUM5.91.60%—39A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has…Sep 18, 2023
CVE-2023-4752HIGH7.80.56%—39Use After Free in GitHub repository vim/vim prior to 9.0.1858.Sep 4, 2023
CVE-2023-4750HIGH7.80.53%—39Use After Free in GitHub repository vim/vim prior to 9.0.1857.Sep 4, 2023
CVE-2023-4733HIGH7.80.54%—39Use After Free in GitHub repository vim/vim prior to 9.0.1840.Sep 4, 2023

Fedora 39.x is EOL — migrate to Fedora 40.x

Fedora 40.x is the next major release. Plan your upgrade before Fedora 39.x stops receiving security patches.

See Fedora 40.x

Add a Fedora 39 EOL badge to your README

Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Fedora 39 EOL status
[![Fedora 39 EOL status](https://eolcanary.com/badge/fedora/39.svg)](https://eolcanary.com/explore/fedora/39)

Frequently asked questions

Is Fedora 39 end of life?

Yes. All Fedora 39.x releases have reached end of life and no longer receive security patches. There are 25 known CVEs affecting Fedora 39.x. Migrate to Fedora 40.x as soon as possible.

What CVEs affect Fedora 39?

There are 25 CVEs tracked for Fedora 39.x and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Fedora 39 version?

The latest Fedora 39.x patch release is 39, released on November 7, 2023. Always run the latest patch to benefit from all security fixes.

How to migrate from Fedora 39 to Fedora 40?

To migrate from Fedora 39 to Fedora 40: (1) review the official Fedora 40 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Fedora 39 in production?

No. Fedora 39 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Fedora 39.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA