Red Hat Enterprise Linux Server RHEL 10 Update Version Red Hat Enterprise Linux 10.0
Views
19
Your rating
Rate update installation process
Log in to rate this update.
Login
Risk factor
No ratings yet. Be the first to rate this update.
Smooth installs
0%
Minor issues
0%
Major issues
0%
AI enhanced content
Update Summary
Red Hat Enterprise Linux 10.0 introduces major installer, security, kernel, storage, networking, and container changes. It also documents removed features, technology previews, and known issues for RHEL 10.0.
Update Details
Security
- System-wide crypto policies, OpenSSL, GnuTLS, NSS, and OpenSSH add post-quantum algorithm support as a Technology Preview.
- OpenSSH 9.9 adds key-agent forwarding restrictions, FIDO improvements, stronger hardening, and removes DSA keys and
pam-ssh-agent. - OpenSSL replaces the deprecated ENGINE API with
pkcs11-providerfor hardware token access. - GnuTLS 3.8.9 and NSS 3.112 add TLS 1.3, PBMAC1, and other cryptographic updates; RSA PKCS #1 v1.5 encryption is disallowed by default.
- SELinux policy and userspace were updated, including new confinement for additional services and
audit2allowCIL output support. - Keylime 7.12 adds IDevID/IAK support, TLS 1.3 by default, and the new
keylime-policytool. - Landlock is introduced as a new Linux Security Module to restrict filesystem access for processes and containers.
- The default crypto policy rejects TLS RSA key exchange and SHA-1 signatures in TLS contexts.
- OpenSC 0.26.1 includes fixes for multiple CVEs: CVE-2024-45615, CVE-2024-45616, CVE-2024-45617, CVE-2024-45618, CVE-2024-45619, and CVE-2024-45620.
- NSS adds ML-DSA and hybrid post-quantum support; a later fix resolves ML-DSA seed corruption after database password changes.
Bug Fixes
- Installer and image creation fixes include improved virtual network device handling, RDP-based remote access, and better Kickstart support for encrypted DNS and CA certificates.
- DNF and RPM management improvements include reduced metadata downloads by default,
dnf --transientsupport, and consistent PGP processing viarpm-sequoia. - Storage and filesystem fixes include XFS, multipath, NVMe, LUKS, and RAID improvements, plus snapshot and atomic write support.
- Identity Management fixes include certificate renewal, LDAP timeout handling, replication behavior, and Directory Server reindexing and health-check improvements.
- Networking fixes include nftables, iptables, firewalld, wpa_supplicant, and NetworkManager improvements, plus VPN TunnelVision mitigation.
- Virtualization fixes include SEV-SNP, live migration, virtiofs, Windows guest, and cloud platform stability improvements.
- System roles received many fixes for podman, storage, network, sshd, bootloader, logging, and HA cluster automation.
- Supportability tools such as
sosandcrashreceived fixes for cleanup, obfuscation, and reporting behavior.
New Features
- RDP replaces VNC for graphical remote access during installation.
- RHEL image builder and bootc-image-builder gain advanced partitioning, Kickstart injection, and improved image customization.
- Kea DHCP replaces ISC DHCP, and
dnsconfdis added for local DNS caching and DNS-over-TLS setup. - The web console gains the
cockpit-filesfile manager. - RHEL system roles add new roles and capabilities, including
aide,sudo, enhancedpodman,systemd,ha_cluster, andstoragefeatures. - RHEL 10 introduces Python 3.12, Ruby 3.3, Node.js 22, Perl 5.40, PHP 8.3, PostgreSQL 16, MySQL 8.4, MariaDB 10.11, GCC 14.2, glibc 2.39, and systemd 257.
- The kernel adds Landlock, atomic write, dynamic EFIVARS pstore switching, a Deadline server for CFS starvation protection, and container-oriented networking improvements.
- Container tooling adds Podman v5 features such as Quadlets for pods, multi-architecture farm builds, OCI artifact support, and persistent
podman updatechanges. - RHEL Lightspeed command-line assistant is introduced.
- Unified Kernel Image (UKI) support is fully available for RHEL cloud and virtualized environments.
Known Issues
- IdM integrated DNS is unavailable or only partially functional in RHEL 10.0.
- NSS database password updates previously corrupted ML-DSA seeds; a later advisory fixes this.
- Encrypted DNS with custom CA can fail during installation when
inst.repoorinst.stage2is used on the kernel command line. - Some installer workflows can become unresponsive during final RPM installation or in rescue mode.
- RHEL 10 cloud and virtualization have several known issues, including NVMe device name changes after reboot and some VM boot or migration limitations.
uname -ianduname -preturn unknown output; useuname -minstead.- The
pkcs11-providerdoes not work correctly in FIPS mode without additional configuration. - RHEL 10 WSL images are self-supported and have limitations such as no FIPS mode and no SELinux enforcing mode.
Hints
- In-place upgrade is supported from RHEL 9.6 to RHEL 10.0 on x86-64-v3, ARMv8.0-A, POWER10, and IBM Z z14; direct upgrade from RHEL 8 to RHEL 10 is not supported.
- RHEL 10 disk images use predictable network interface names by default, and
net.ifnames=0has been removed from image arguments. - The RPM database moved from
/var/lib/rpmto/usr/lib/sysimage/rpm. - RHEL 10 uses cgroup v2 by default; cgroup v1 and the
runcruntime are removed. - Postfix now uses LMDB by default; Berkeley DB is no longer available and existing databases may need conversion after upgrade.
- Custom SELinux modules that reference
/var/runshould be updated to/run. - System V init scripts,
authconfig,fips-mode-setup, and several legacy installer and networking options are removed. - For RHEL 10 containers,
podman system migrate --new-runtime=crunmay be needed after upgrade from older releases. - The
storage.conffile moved to/usr/share/containers. - The
cockpit-composerpackage is deprecated in favor ofcockpit-image-builder.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 10
Version: Red Hat Enterprise Linux 10.0
Vendor release date: May 20, 2025
Original release notes: View on vendor site
Published on updatealert.io: Jul 31, 2026