Views
20

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 10.1 release notes cover major installer, security, kernel, networking, virtualization, and management updates. They also document known issues, deprecated features, and in-place upgrade guidance for RHEL 10.1. Reference IDs: RHSA-2023:3722, RHBA-2026:3809.

Update Details

Security

  • System-wide crypto policies enable post-quantum cryptography (PQC) by default, including hybrid ML-KEM and ML-DSA support across OpenSSL, GnuTLS, NSS, and Sequoia PGP.
  • OpenSSL 3.5 adds ML-KEM, ML-DSA, and SLH-DSA support, hybrid ML-KEM TLS groups, QUIC support, and sslkeylogfile; SHA-224 is disabled.
  • NSS 3.112 adds ML-DSA and hybrid ML-KEM support; a known issue in this release corrupting ML-DSA seeds on password change is fixed by an advisory.
  • OpenSSH now supports Kerberos authentication indicators and ignores invalid short RSA host keys in known_hosts.
  • SELinux policy changes confine additional services, move EPEL-related modules to -extra subpackages, and remove several services from permissive mode.
  • DNS over TLS is generally available for securing DNS traffic, and IdM also offers DoT as a Technology Preview.
  • The fwctl kernel subsystem provides a standardized secure firmware RPC interface for software-defined devices.
  • fapolicyd fixes prevent RPM database crashes during repeated updates, and container startup workarounds are documented when fapolicyd is enabled.
  • pkcs11-provider has a known FIPS-mode limitation with cryptographic tokens; a workaround is documented.
  • SSLKEYLOGFILE support is added to OpenSSL, but it is explicitly security-sensitive and intended only for test/debug use.

Bug Fixes

  • Installation no longer fails when removing a pre-existing LVM VDO volume without dm_vdo support.
  • The installer now respects BOOTIF, and several Kickstart and storage-related installation failures are fixed.
  • chronyc reload sources now handles hostname-based sources correctly.
  • iproute2 custom settings in /etc/iproute2/ are preserved and work as expected after upgrade.
  • The kernel no longer panics when SR-IOV VF counts are reduced at runtime.
  • multipathd now monitors devices with offline paths and supports file-based sockets.
  • Pacemaker and pcs receive multiple fixes for validation, fencing safety, output formats, cluster rename, and long-running systemd resources.
  • glibc fixes crashes in auditing mode, recursive dlopen, ctype.h use in multithreaded namespaces, and incomplete group membership results.
  • virtiofsd no longer crashes with many open files; VM migration and SEV-SNP boot issues are also fixed.
  • sos now limits coredump collection, redacts iSCSI CHAP credentials, and preserves unrelated plugin options when using -k.
  • 389-ds-base fixes numerous Directory Server, LMDB, replication, and monitoring issues.
  • rhel-system-roles fixes multiple role behaviors, including SELinux persistence, bootloader option removal, podman formatting, network validation, and cluster exports.

New Features

  • Installer now offers a fips=1 boot menu entry, soft reboots, and rpm in the installation environment.
  • RHEL Image Builder adds a new CLI experience, WSL2 image support, vagrant-libvirt images, and URI-based blueprint file references.
  • RHEL 10.1 introduces support for RPMv6 signatures and OpenPGP v6 verification with Sequoia PGP.
  • NetworkManager and Nmstate add IPv4 forwarding per interface, fixed IPv6 prefix delegation subnet IDs, FEC settings, route options, and NBFT parsing.
  • The web console is rebased to Cockpit 344 with PatternFly 6 and improved storage, VM, networking, and branding support.
  • GCC Toolset 15, LLVM 20, Rust 1.88.0, GDB 16.3, Valgrind 3.25.1, SystemTap 5.3, and OpenJDK 25 are available.
  • RHEL now supports AI accelerator driver installation through the new rhel-drivers tool and Red Hat-delivered partner drivers.
  • Virtualization gains features such as virtio-mem on IBM Z, SCSI passthrough, SCSI3 persistent reservations, direct kernel boot for SecureBoot VMs, and new live migration options.
  • IdM-to-IdM migration is now fully supported, and HSM support for IdM CA/KRA keys is now fully supported.
  • RHEL Lightspeed adds image-mode support for the command-line assistant and increases its input context limit to 32 KB.

Known Issues

  • Crash dumps are not performed by default for image mode installations unless crashkernel= is set.
  • Podman and bootc use different registry login processes, so Podman login does not automatically authenticate bootc image switching.
  • fapolicyd can block container startup unless a documented rule workaround is applied.
  • sq cannot generate keys in FIPS mode.
  • uname -i and uname -p produce unknown output; use uname -m instead.
  • Some virtualization scenarios remain limited, including Windows VM issues, IBM Z live dump/snapshot instability, and certain SEV-SNP boot limitations.
  • kTLS still has known limitations for session key updates and TLS 1.3 NIC offload.
  • PostgreSQL, MariaDB, and MySQL do not work in image mode due to missing user/workdir initialization.
  • The command-line assistant has several known limitations, including Satellite CA trust handling and delayed config reloads.

Hints

  • Supported in-place upgrade paths are from RHEL 9.6 to RHEL 10.0 and from RHEL 9.7 to RHEL 10.1 on x86-64-v3, ARMv8.0-A, POWER10, and IBM Z z15 or later.
  • On 64-bit ARM, in-place upgrades require the 4k page size kernel; 64k page size is not supported by Leapp.
  • RHEL 8 cannot be upgraded directly to RHEL 10; upgrade to RHEL 9 first, then to RHEL 10.
  • OpenSSL 3.5 uses standard formats for ML-KEM and ML-DSA keys; older oqsprovider-generated keys must be converted with openssl pkcs8.
  • gcc-toolset-15 no longer uses scl enable; use gcc-toolset-15-env instead.
  • bootc-image-builder now uses local container storage by default, so base images must be preloaded locally before building disk images.
  • For FIPS mode during installation, use the new boot menu entry or add fips=1 at install start; RHEL 10 does not support switching an installed system to FIPS later.
  • tzdata is no longer installed by default in minimal container images; install it explicitly if needed.
  • libvirtd, virt-manager, teamd, and several older virtualization and networking features are deprecated or removed; plan migrations accordingly.
  • modularity is deprecated in RHEL 10, and no modular Application Streams are distributed.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 10

Version: 10.1

Vendor release date: Nov 11, 2025

Original release notes: View on vendor site

Published on updatealert.io: Jul 31, 2026