Opensuse 13.x — End of Life

EOL Actively exploited
EOL: Jan 17, 20172 releases in this series9 CVEs

Opensuse 13.x reached end of life on Jan 17, 2017, 3550 days ago, and no longer receives security fixes. 9 CVEs are tracked for this series, including 2 critical and 2 actively exploited according to CISA KEV. 4 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Opensuse 15. See Opensuse 15 →

Opensuse 13.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
13.2Nov 4, 2014—Jan 17, 2017—EOL
13.1Jan 8, 2014—Feb 3, 2016—EOL

CVEs affecting Opensuse 13.x (11)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2016-9842HIGH8.85.20%—13.2The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact v…May 23, 2017
CVE-2016-9841CRITICAL9.87.55%—13.2inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe…May 23, 2017
CVE-2016-9840HIGH8.84.79%—13.2inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper point…May 23, 2017
CVE-2016-4117CRITICAL9.894.35% KEV 13.1Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as …May 11, 2016
CVE-2016-4117CRITICAL9.894.35% KEV 13.2Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as …May 11, 2016
CVE-2015-8036MEDIUM6.82.89%—13.2Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SS…Nov 2, 2015
CVE-2015-5291MEDIUM6.83.65%—13.2Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.…Nov 2, 2015
CVE-2015-3246MEDIUM5.18.43% KEV 13.2libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod…Aug 11, 2015
CVE-2015-2808LOW3.773.85%—13.1The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data duri…Apr 1, 2015
CVE-2015-2808LOW3.773.85%—13.2The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data duri…Apr 1, 2015
CVE-2014-3566LOW3.499.99%—13.1The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which mak…Oct 15, 2014

Opensuse 13.x is EOL — migrate to Opensuse 15.x

Opensuse 15.x is the next major release. Plan your upgrade before Opensuse 13.x stops receiving security patches.

See Opensuse 15.x

Add a Opensuse 13 EOL badge to your README

Show your users which Opensuse version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Opensuse 13 EOL status
[![Opensuse 13 EOL status](https://eolcanary.com/badge/opensuse/13.svg)](https://eolcanary.com/explore/opensuse/13)

Frequently asked questions

Is Opensuse 13 end of life?

Yes. All Opensuse 13.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting Opensuse 13.x, including 2 critical. Migrate to Opensuse 15.x as soon as possible.

What CVEs affect Opensuse 13?

There are 9 CVEs tracked for Opensuse 13.x, including 2 critical severity issues and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Opensuse 13 version?

Check the version table above for the latest Opensuse 13.x patch release.

How to migrate from Opensuse 13 to Opensuse 15?

To migrate from Opensuse 13 to Opensuse 15: (1) review the official Opensuse 15 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Opensuse 13 in production?

No. Opensuse 13 has reached end of life and security vulnerabilities are no longer patched. Critically, 2 CVEs affecting Opensuse 13.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA