Opensuse 13.x — End of Life
EOL Actively exploitedOpensuse 13.x reached end of life on Jan 17, 2017, 3550 days ago, and no longer receives security fixes. 9 CVEs are tracked for this series, including 2 critical and 2 actively exploited according to CISA KEV. 4 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Opensuse 15. See Opensuse 15 →
Opensuse 13.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 13.2 | Nov 4, 2014 | — | Jan 17, 2017 | — | EOL | |
| 13.1 | Jan 8, 2014 | — | Feb 3, 2016 | — | EOL |
CVEs affecting Opensuse 13.x (11)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-9842 | HIGH | 8.8 | 5.20% | — | 13.2 | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact v… | May 23, 2017 |
| CVE-2016-9841 | CRITICAL | 9.8 | 7.55% | — | 13.2 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe… | May 23, 2017 |
| CVE-2016-9840 | HIGH | 8.8 | 4.79% | — | 13.2 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper point… | May 23, 2017 |
| CVE-2016-4117 | CRITICAL | 9.8 | 94.35% | KEV | 13.1 | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as … | May 11, 2016 |
| CVE-2016-4117 | CRITICAL | 9.8 | 94.35% | KEV | 13.2 | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as … | May 11, 2016 |
| CVE-2015-8036 | MEDIUM | 6.8 | 2.89% | — | 13.2 | Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SS… | Nov 2, 2015 |
| CVE-2015-5291 | MEDIUM | 6.8 | 3.65% | — | 13.2 | Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.… | Nov 2, 2015 |
| CVE-2015-3246 | MEDIUM | 5.1 | 8.43% | KEV | 13.2 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod… | Aug 11, 2015 |
| CVE-2015-2808 | LOW | 3.7 | 73.85% | — | 13.1 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data duri… | Apr 1, 2015 |
| CVE-2015-2808 | LOW | 3.7 | 73.85% | — | 13.2 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data duri… | Apr 1, 2015 |
| CVE-2014-3566 | LOW | 3.4 | 99.99% | — | 13.1 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which mak… | Oct 15, 2014 |
Opensuse 13.x is EOL — migrate to Opensuse 15.x
Opensuse 15.x is the next major release. Plan your upgrade before Opensuse 13.x stops receiving security patches.
Add a Opensuse 13 EOL badge to your README
Show your users which Opensuse version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/opensuse/13)Frequently asked questions
Is Opensuse 13 end of life?
Yes. All Opensuse 13.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting Opensuse 13.x, including 2 critical. Migrate to Opensuse 15.x as soon as possible.
What CVEs affect Opensuse 13?
There are 9 CVEs tracked for Opensuse 13.x, including 2 critical severity issues and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Opensuse 13 version?
Check the version table above for the latest Opensuse 13.x patch release.
How to migrate from Opensuse 13 to Opensuse 15?
To migrate from Opensuse 13 to Opensuse 15: (1) review the official Opensuse 15 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Opensuse 13 in production?
No. Opensuse 13 has reached end of life and security vulnerabilities are no longer patched. Critically, 2 CVEs affecting Opensuse 13.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
