Fedora 40.x — End of Life
EOL High riskFedora 40.x reached end of life on May 13, 2025, 512 days ago, and no longer receives security fixes. The most recent release in this series is 40. 13 CVEs are tracked for this series. The next major version is Fedora 41. See Fedora 41 →
Fedora 40.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 40 | Apr 23, 2024 | — | May 13, 2025 | 40 | EOL |
CVEs affecting Fedora 40.x (13)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-35949 | HIGH | 7.8 | 0.24% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: btrfs: make sure that WRITTEN is set on all metadat… | May 20, 2024 |
| CVE-2024-27401 | HIGH | 7.8 | 0.29% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into ac… | May 14, 2024 |
| CVE-2024-27400 | HIGH | 7.8 | 0.24% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_t… | May 14, 2024 |
| CVE-2024-27398 | HIGH | 8.0 | 0.82% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_so… | May 14, 2024 |
| CVE-2024-27019 | HIGH | 7.8 | 0.21% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __… | May 1, 2024 |
| CVE-2024-27018 | HIGH | 8.2 | 0.63% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook … | May 1, 2024 |
| CVE-2024-27017 | HIGH | 7.8 | 0.29% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view o… | May 1, 2024 |
| CVE-2024-27016 | HIGH | 7.1 | 0.33% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure… | May 1, 2024 |
| CVE-2024-27012 | MEDIUM | 5.5 | 0.27% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when del… | May 1, 2024 |
| CVE-2024-26994 | HIGH | 7.8 | 0.29% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a c… | May 1, 2024 |
| CVE-2024-22373 | HIGH | 8.1 | 1.65% | — | 40 | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater… | Apr 25, 2024 |
| CVE-2024-26922 | HIGH | 7.8 | 0.31% | — | 40 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o… | Apr 23, 2024 |
| CVE-2024-28960 | HIGH | 8.2 | 0.84% | — | 40 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C… | Mar 29, 2024 |
Fedora 40.x is EOL — migrate to Fedora 41.x
Fedora 41.x is the next major release. Plan your upgrade before Fedora 40.x stops receiving security patches.
Add a Fedora 40 EOL badge to your README
Show your users which Fedora version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/fedora/40)Frequently asked questions
Is Fedora 40 end of life?
Yes. All Fedora 40.x releases have reached end of life and no longer receive security patches. There are 13 known CVEs affecting Fedora 40.x. Migrate to Fedora 41.x as soon as possible.
What CVEs affect Fedora 40?
There are 13 CVEs tracked for Fedora 40.x. See the full list above with CVSS and EPSS scores.
What is the latest Fedora 40 version?
The latest Fedora 40.x patch release is 40, released on April 23, 2024. Always run the latest patch to benefit from all security fixes.
How to migrate from Fedora 40 to Fedora 41?
To migrate from Fedora 40 to Fedora 41: (1) review the official Fedora 41 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Fedora 40 in production?
No. Fedora 40 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
