Red Hat Enterprise Linux Server RHEL 10 Update Version 10.1
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 10.1 release notes cover major installer, security, kernel, networking, virtualization, and management updates. They also document known issues, deprecated features, and in-place upgrade guidance for RHEL 10.1. Reference IDs: RHSA-2023:3722, RHBA-2026:3809.
Update Details
Security
- System-wide crypto policies enable post-quantum cryptography (PQC) by default, including hybrid ML-KEM and ML-DSA support across OpenSSL, GnuTLS, NSS, and Sequoia PGP.
- OpenSSL 3.5 adds ML-KEM, ML-DSA, and SLH-DSA support, hybrid ML-KEM TLS groups, QUIC support, and
sslkeylogfile; SHA-224 is disabled. - NSS 3.112 adds ML-DSA and hybrid ML-KEM support; a known issue in this release corrupting ML-DSA seeds on password change is fixed by an advisory.
- OpenSSH now supports Kerberos authentication indicators and ignores invalid short RSA host keys in
known_hosts. - SELinux policy changes confine additional services, move EPEL-related modules to
-extrasubpackages, and remove several services from permissive mode. - DNS over TLS is generally available for securing DNS traffic, and IdM also offers DoT as a Technology Preview.
- The
fwctlkernel subsystem provides a standardized secure firmware RPC interface for software-defined devices. fapolicydfixes prevent RPM database crashes during repeated updates, and container startup workarounds are documented whenfapolicydis enabled.pkcs11-providerhas a known FIPS-mode limitation with cryptographic tokens; a workaround is documented.SSLKEYLOGFILEsupport is added to OpenSSL, but it is explicitly security-sensitive and intended only for test/debug use.
Bug Fixes
- Installation no longer fails when removing a pre-existing LVM VDO volume without
dm_vdosupport. - The installer now respects
BOOTIF, and several Kickstart and storage-related installation failures are fixed. chronyc reload sourcesnow handles hostname-based sources correctly.iproute2custom settings in/etc/iproute2/are preserved and work as expected after upgrade.- The kernel no longer panics when SR-IOV VF counts are reduced at runtime.
multipathdnow monitors devices with offline paths and supports file-based sockets.- Pacemaker and
pcsreceive multiple fixes for validation, fencing safety, output formats, cluster rename, and long-running systemd resources. glibcfixes crashes in auditing mode, recursivedlopen,ctype.huse in multithreaded namespaces, and incomplete group membership results.virtiofsdno longer crashes with many open files; VM migration and SEV-SNP boot issues are also fixed.sosnow limits coredump collection, redacts iSCSI CHAP credentials, and preserves unrelated plugin options when using-k.389-ds-basefixes numerous Directory Server, LMDB, replication, and monitoring issues.rhel-system-rolesfixes multiple role behaviors, including SELinux persistence, bootloader option removal, podman formatting, network validation, and cluster exports.
New Features
- Installer now offers a
fips=1boot menu entry, soft reboots, andrpmin the installation environment. - RHEL Image Builder adds a new CLI experience, WSL2 image support,
vagrant-libvirtimages, and URI-based blueprint file references. - RHEL 10.1 introduces support for RPMv6 signatures and OpenPGP v6 verification with Sequoia PGP.
- NetworkManager and Nmstate add IPv4 forwarding per interface, fixed IPv6 prefix delegation subnet IDs, FEC settings, route options, and NBFT parsing.
- The web console is rebased to Cockpit 344 with PatternFly 6 and improved storage, VM, networking, and branding support.
- GCC Toolset 15, LLVM 20, Rust 1.88.0, GDB 16.3, Valgrind 3.25.1, SystemTap 5.3, and OpenJDK 25 are available.
- RHEL now supports AI accelerator driver installation through the new
rhel-driverstool and Red Hat-delivered partner drivers. - Virtualization gains features such as virtio-mem on IBM Z, SCSI passthrough, SCSI3 persistent reservations, direct kernel boot for SecureBoot VMs, and new live migration options.
- IdM-to-IdM migration is now fully supported, and HSM support for IdM CA/KRA keys is now fully supported.
- RHEL Lightspeed adds image-mode support for the command-line assistant and increases its input context limit to 32 KB.
Known Issues
- Crash dumps are not performed by default for image mode installations unless
crashkernel=is set. - Podman and bootc use different registry login processes, so Podman login does not automatically authenticate bootc image switching.
fapolicydcan block container startup unless a documented rule workaround is applied.sqcannot generate keys in FIPS mode.uname -ianduname -pproduce unknown output; useuname -minstead.- Some virtualization scenarios remain limited, including Windows VM issues, IBM Z live dump/snapshot instability, and certain SEV-SNP boot limitations.
kTLSstill has known limitations for session key updates and TLS 1.3 NIC offload.- PostgreSQL, MariaDB, and MySQL do not work in image mode due to missing user/workdir initialization.
- The command-line assistant has several known limitations, including Satellite CA trust handling and delayed config reloads.
Hints
- Supported in-place upgrade paths are from RHEL 9.6 to RHEL 10.0 and from RHEL 9.7 to RHEL 10.1 on x86-64-v3, ARMv8.0-A, POWER10, and IBM Z z15 or later.
- On 64-bit ARM, in-place upgrades require the 4k page size kernel; 64k page size is not supported by Leapp.
- RHEL 8 cannot be upgraded directly to RHEL 10; upgrade to RHEL 9 first, then to RHEL 10.
- OpenSSL 3.5 uses standard formats for ML-KEM and ML-DSA keys; older oqsprovider-generated keys must be converted with
openssl pkcs8. gcc-toolset-15no longer usesscl enable; usegcc-toolset-15-envinstead.bootc-image-buildernow uses local container storage by default, so base images must be preloaded locally before building disk images.- For FIPS mode during installation, use the new boot menu entry or add
fips=1at install start; RHEL 10 does not support switching an installed system to FIPS later. tzdatais no longer installed by default in minimal container images; install it explicitly if needed.libvirtd,virt-manager,teamd, and several older virtualization and networking features are deprecated or removed; plan migrations accordingly.modularityis deprecated in RHEL 10, and no modular Application Streams are distributed.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 10
Version: 10.1
Vendor release date: Nov 11, 2025
Original release notes: View on vendor site
Published on updatealert.io: Jul 31, 2026