Views
22

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 10.2 introduces new security capabilities, updated core components, and expanded hardware support. It also adds major installer, networking, storage, virtualization, and system role enhancements for RHEL 10.2.

Update Details

Security

  • OpenSSH adds ML-KEM hybrid key exchange in FIPS mode, and CanonicalMatchUser helps prevent privilege escalation with capitalized AD usernames.
  • libssh adds post-quantum hybrid key exchange methods based on ML-KEM, and crypto-policies enables them by default.
  • fapolicyd is rebased to 1.4.3 with rule filtering, and SELinux now confines services such as redfish-finder, systemd-oomd, and new OpenSSH binaries more tightly.
  • p11-kit 0.26.1 adds PKCS #11 v3.2 headers with PQC support, and podman-sequoia supports composite post-quantum signatures.
  • Keylime and keylime-agent are rebased with push attestation, expanded TPM ECC support, and fixes for ECC certificate enrollment and quote verification.
  • The restorecon -c option reports relabeled files, and setfiles -A reduces memory use on large file systems.
  • The foomatic-rip filter now rejects unrecognized PPD values to reduce printing-related security risk.
  • The crypto-policies package enables ML-KEM for OpenSSH and libssh, including FIPS-mode support for NIST hybrid key exchanges.
  • The fapolicyd-selinux update prevents SIGSTOP and ptrace() from hanging fapolicyd.

Bug Fixes

  • Installer and image creation fixes include correct root password handling in ISO images, better bootc/ostree installation behavior, and improved Kickstart handling.
  • Networking fixes include SR-IOV reapply support, better DNS search-domain handling, improved nftables behavior, and more reliable NetworkManager and nmstate operation.
  • Kernel and performance tooling fixes include perf, ftrace, valgrind, SystemTap, elfutils, crash, and BPF updates with stability and compatibility improvements.
  • Storage fixes include more robust multipath persistent reservations, improved VDO metadata handling, and better iSCSI LUN handling during installation.
  • Identity Management fixes include Directory Server replication, cache, and import improvements, plus adcli and SSSD reliability fixes.
  • Container tooling fixes include Podman, Buildah, Skopeo, crun, and fuse-overlayfs updates, including improved token handling and Quadlet support.
  • Virtualization fixes include live migration, virtiofsd file descriptor exhaustion, vTPM migration, and IBM Z VM boot and memory handling improvements.
  • glibc fixes improve stdio, NSS lookup stability, DNS query handling, sem_open, freopen, and locale/package behavior.
  • DNF and RPM fixes improve signature handling, version comparison, protected package removal behavior, and support for non-local user/group ownership.

New Features

  • Anaconda can automatically install Flatpaks during installation, including from Red Hat Satellite.
  • A new rdp Kickstart command enables remote graphical installations.
  • The default /boot partition size increases to 2 GiB.
  • RHEL image builder gains GUI support, PXE stateless image creation, and Anaconda network installer image generation.
  • OpenSSH, libssh, p11-kit, and crypto-policies add post-quantum cryptography support.
  • RHEL 10.2 adds PostgreSQL 18, MariaDB 11.8, PHP 8.4, Python 3.14, Ruby 4.0, and updated toolchains.
  • RHEL for Edge adds fully supported FDO client/server packages and greenboot-rs.
  • Networking gains PRP/HSR support, WiFi 7 support, threaded NAPI busy polling, and nftables policy sets.
  • Virtualization adds new libvirt, QEMU, and guest features including viosock for Windows VMs, TDX PCCS, and Secure Boot for ARM64 VMs as Technology Preview.
  • RHEL Lightspeed adds color output and SAP Solutions documentation.

Known Issues

  • Boot container installation in UEFI mode fails without a separate /boot partition.
  • kdump cannot be activated with Secure Boot on 64-bit ARM.
  • SELinux prevents replication in a Galera cluster after upgrading MariaDB 10.11 to 11.8.
  • ipa-migrate does not migrate SSH public keys.
  • EUS repositories are not enabled by default on RHEL 10 systems.
  • Firmware flash updates may fail on certain Marvell QLogic Fibre Channel adapters.
  • Some Windows VM and IBM Z virtualization scenarios still have boot, validation, or stability issues.
  • The goose-redhat package can be deleted during a Leapp upgrade unless the target repository is enabled.
  • rust-rpm-sequoia fails when importing OpenPGP certificates with keys disallowed by crypto-policies.

Hints

  • Supported in-place upgrade paths are from RHEL 9.6 to RHEL 10.0 and from RHEL 9.8 to RHEL 10.2 on supported architectures.
  • RHEL 8 cannot be upgraded directly to RHEL 10; upgrade to RHEL 9 first, then to RHEL 10.
  • The release notes state that RHEL 10.2 is distributed with kernel 6.12.0-211.7.3.
  • Flatpaks are now the default delivery method for Mozilla Firefox and Mozilla Thunderbird, but RPM packages remain available.
  • The microcode.force_minrev= kernel parameter has been removed; use microcode= with force_minrev instead.
  • The mitigations= kernel parameter now also disables vmscape mitigation when set to off on x86.
  • The bootc-image-builder tool is deprecated; use RHEL image builder instead.
  • The vi command no longer launches Vim when both vim-minimal and vim-enhanced are installed.
  • SCTP transport for knet in Corosync is deprecated.
  • The FUTURE crypto policy now allows only hybrid ML-KEM key exchange methods.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 10

Version: 10.2

Vendor release date: May 19, 2026

Original release notes: View on vendor site

Published on updatealert.io: Jul 31, 2026