Fedora Linux 21
Fedora Linux 21
The Fedora Linux 21 reached end of service life on Dec 1, 2015 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Fedora Linux 21 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- fedora
- release
- 21
- product Label
- Fedora Linux
- release Label
- 21
- codename
- lts
- latest Version
- release Date
- 2014-12-09
- maintained
- source Url
- https://endoflife.date/fedora
Lifecycle Dates
- End of Service Life
- Dec 1, 2015
- Last OEM Support
- Dec 1, 2015
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Fedora Linux 21 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Fedora Linux 21?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Fedora Linux 21 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Fedora Linux 21 Support: Frequently Asked Questions
Is the Fedora Linux 21 still supported?
Fedora ended support for the Fedora Linux 21 on Dec 1, 2015 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Fedora Linux 21 end of service life (EOSL) date?
Fedora lists the end of service life for the Fedora Linux 21 as Dec 1, 2015.
Can I keep using the Fedora Linux 21 after its EOSL date?
Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Fedora Linux 21 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Fedora Linux 21
189 published CVEs affect the Fedora Linux 21, including 74 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2014-8089 | CRITICAL | 9.8 | Feb 17, 2020 | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte. |
| CVE-2019-11235 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499. |
| CVE-2019-11234 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
| CVE-2015-5740 | CRITICAL | 9.8 | Oct 18, 2017 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers. |
| CVE-2015-5739 | CRITICAL | 9.8 | Oct 18, 2017 | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length." |
| CVE-2015-6816 | CRITICAL | 9.8 | Aug 9, 2017 | ganglia-web before 3.7.1 allows remote attackers to bypass authentication. |
| CVE-2015-0278 | HIGH | 10.0 | May 18, 2015 | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. |
| CVE-2015-2806 | HIGH | 10.0 | Apr 10, 2015 | Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors. |
| CVE-2015-5165 | HIGH | 9.3 | Aug 12, 2015 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. |
| CVE-2019-10132 | HIGH | 8.8 | May 22, 2019 | A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. |
| CVE-2015-5607 | HIGH | 8.8 | Sep 20, 2017 | Cross-site request forgery in the REST API in IPython 2 and 3. |
| CVE-2015-1779 | HIGH | 8.6 | Jan 12, 2016 | The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section. |
| CVE-2015-6566 | HIGH | 8.4 | Jan 11, 2016 | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. |
| CVE-2010-4661 | HIGH | 7.8 | Nov 13, 2019 | udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
| CVE-2014-7272 | HIGH | 7.8 | Mar 8, 2018 | Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases). |
| CVE-2014-7271 | HIGH | 7.8 | Mar 8, 2018 | Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
| CVE-2018-5345 | HIGH | 7.8 | Jan 12, 2018 | A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
| CVE-2015-5704 | HIGH | 7.8 | Sep 25, 2017 | scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. |
| CVE-2014-9114 | HIGH | 7.8 | Mar 31, 2017 | Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. |
| CVE-2015-4047 | HIGH | 7.8 | May 29, 2015 | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. |
Showing the 20 most severe of 189 known CVEs.
Get Third Party Support