Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.2 introduces new installer, security, networking, storage, virtualization, and management features, plus notable bug fixes and technology previews. It also includes security updates such as CVE-2019-14287 and CVE-2019-19232 in sudo.

Update Details

Security

  • System-wide cryptographic policies can now be customized, including full policy definitions or selective changes.
  • The web console adds a session timeout to improve security.
  • RHEL 8.2 includes DISA STIG, ACSC Essential Eight, and additional SELinux analysis tools for hardening and compliance.
  • oscap-podman is added for security and compliance scanning of containers.
  • SELinux now supports confined operation for more services, including lldpd, rrdcached, stratisd, and timedatex.
  • sudo fixes privilege escalation issues CVE-2019-14287 and CVE-2019-19232.
  • rngd can run with non-root privileges to improve system security.
  • Recursive DNS queries are disabled by default on IdM servers with integrated DNS to reduce DNS amplification risk.
  • The default container registry search list is restricted to trusted registries to reduce image spoofing risk.
  • Podman FIPS handling requires running update-crypto-policies --set FIPS inside containers before application code.

Bug Fixes

  • Installer fixes include better handling of version/inst.version, secure boot on s390x, boot-device limits, and Kickstart image source issues.
  • yum repolist no longer stops at the first unavailable repository.
  • ReaR updates improve build directory handling, recovery behavior, and bootable ISO creation.
  • Networking fixes include dnsmasq handling of non-recursive queries, DHCP renewal after time changes, and nftables command parsing.
  • Kernel fixes address crashes, memory hotplug issues, RPS/XPS CPU isolation, and vmcore capture problems.
  • Storage fixes include VDO import support, dm-writecache support, and multipath startup improvements.
  • Identity Management fixes include dsctl instance-name parsing, Directory Server buffer sizing, and improved DNS record handling for AD trust.
  • Virtualization fixes include better VM boot handling on newer Intel CPUs, Azure cloud-init provisioning, and ESXi clone reboot behavior.
  • glibc, ltrace, make, and other toolchain components received stability and correctness fixes.

New Features

  • Register and subscribe during installation, including CDN installs and Red Hat Insights registration.
  • Tuned 2.13 adds architecture-dependent tuning and multiple include directives.
  • Python 3.8 and Maven 3.6 are available as new module streams.
  • Identity Management adds Healthcheck and Ansible roles/modules for installation and management.
  • The web console is redesigned with PatternFly 4 and gains client-certificate login support.
  • eBPF for tc is fully supported, and BCC tools/libraries are supported in RHEL 8.2.
  • Control Group v2 is fully supported.
  • New storage and filesystem capabilities include dm-writecache, VDO import, and NVMe surprise removal support.
  • GCC Toolset 9, LLVM Toolset 9.0.1, Rust Toolset 1.41, Go Toolset 1.13, and OpenJDK secp256k1 support are included.
  • New container and registry capabilities include skopeo sync, skopeo login/logout, podman system reset, and containers.conf.

Known Issues

  • The auth and authconfig Kickstart commands require the AppStream repository.
  • reboot --kexec and inst.kexec do not provide a predictable system state.
  • Network access is not enabled by default in the installer.
  • Wayland has functional limitations, including no X11-style display tools and limited remote forwarding support.
  • SELINUX=disabled in /etc/selinux/config does not fully disable SELinux at boot; use selinux=0 on the kernel command line if needed.
  • The /boot file system cannot be placed on LVM.
  • LVM writecache has several limitations, including no snapshots while attached.
  • Some SSSD and IdM scenarios have known limitations, including large AD group membership retrieval and LDAP TLS defaults.
  • Several virtualization, storage, and security edge cases remain unresolved, including some VM boot, snapshot, and OpenSCAP limitations.

Hints

  • Supported in-place upgrade paths are from RHEL 7.9 to RHEL 8.2 on x86_64, IBM POWER8 LE, and IBM Z, and from RHEL 7.6 to RHEL 8.2 on 64-bit ARM, IBM POWER9 LE, and IBM Z Structure A.
  • For RHEL 8.2 installations, the Binary DVD ISO is larger than 4.7 GB and may require dual-layer DVD or USB media.
  • The supported kernel version for RHEL 8.2 is 4.18.0-193.
  • The default container registry search list now favors trusted Red Hat and partner registries; use fully qualified image names to avoid spoofing.
  • SMB1 is disabled by default in Samba; re-enable only if absolutely required.
  • TLS 1.0 and TLS 1.1 are deprecated and disabled in the DEFAULT crypto policy; use LEGACY only when necessary.
  • Several deprecated Kickstart commands and options now emit warnings, including auth, authconfig, device, dmraid, and reboot --kexec.
  • The release notes explicitly recommend backing up Samba TDB files before starting Samba after upgrade.
  • For container FIPS compliance, run update-crypto-policies --set FIPS inside the container before application code executes.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: RHEL 8.2 (kernel 4.18.0-193)

Vendor release date: Apr 28, 2020

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026