Fedora Linux 34
Fedora Linux 34
The Fedora Linux 34 reached end of service life on Jun 7, 2022 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Fedora Linux 34 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- fedora
- release
- 34
- product Label
- Fedora Linux
- release Label
- 34
- codename
- lts
- latest Version
- release Date
- 2021-04-27
- maintained
- source Url
- https://endoflife.date/fedora
Lifecycle Dates
- End of Service Life
- Jun 7, 2022
- Last OEM Support
- Jun 7, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Fedora Linux 34 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Fedora Linux 34?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Fedora Linux 34 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Fedora Linux 34 Support: Frequently Asked Questions
Is the Fedora Linux 34 still supported?
Fedora ended support for the Fedora Linux 34 on Jun 7, 2022 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Fedora Linux 34 end of service life (EOSL) date?
Fedora lists the end of service life for the Fedora Linux 34 as Jun 7, 2022.
Can I keep using the Fedora Linux 34 after its EOSL date?
Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Fedora Linux 34 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Fedora Linux 34
1206 published CVEs affect the Fedora Linux 34, including 666 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-24884 | CRITICAL | 10.0 | May 6, 2022 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI co |
| CVE-2021-44228 | CRITICAL | 10.0 | Dec 10, 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along wit |
| CVE-2021-3781 | CRITICAL | 9.9 | Feb 16, 2022 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
| CVE-2022-30600 | CRITICAL | 9.8 | May 18, 2022 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. |
| CVE-2022-30599 | CRITICAL | 9.8 | May 18, 2022 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. |
| CVE-2022-29502 | CRITICAL | 9.8 | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| CVE-2022-27404 | CRITICAL | 9.8 | Apr 22, 2022 | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. |
| CVE-2022-0547 | CRITICAL | 9.8 | Mar 18, 2022 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. |
| CVE-2022-23943 | CRITICAL | 9.8 | Mar 14, 2022 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. |
| CVE-2022-22720 | CRITICAL | 9.8 | Mar 14, 2022 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
| CVE-2022-26496 | CRITICAL | 9.8 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name. |
| CVE-2022-26495 | CRITICAL | 9.8 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages. |
| CVE-2022-0730 | CRITICAL | 9.8 | Mar 3, 2022 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. |
| CVE-2022-25315 | CRITICAL | 9.8 | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
| CVE-2021-3773 | CRITICAL | 9.8 | Feb 16, 2022 | A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks. |
| CVE-2022-25235 | CRITICAL | 9.8 | Feb 16, 2022 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. |
| CVE-2021-41816 | CRITICAL | 9.8 | Feb 6, 2022 | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby. |
| CVE-2021-44790 | CRITICAL | 9.8 | Dec 20, 2021 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. |
| CVE-2021-44847 | CRITICAL | 9.8 | Dec 13, 2021 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet. |
| CVE-2021-44143 | CRITICAL | 9.8 | Nov 22, 2021 | A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution. |
Showing the 20 most severe of 1206 known CVEs.
Get Third Party Support