Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.3 adds RHEL for Edge, updated installer and Image Builder workflows, new module streams, and major security/compliance updates. It also includes kernel, networking, virtualization, storage, and identity management enhancements for RHEL 8.3. Reference IDs: RHBA-2021:0569, RHEA-2020:5101.

Update Details

Security

  • OpenSCAP, SCAP Security Guide, and related compliance content were updated, including new CIS RHEL 8, CIS RHEL 7, HIPAA, and NIST-800-171 profiles.
  • libssh was rebased to 0.9.4 and fixes CVE-2019-14889 and CVE-2020-1730.
  • OpenSC was rebased to 0.20.0 and fixes CVE-2019-6502, CVE-2019-15946, CVE-2019-15945, CVE-2019-19480, CVE-2019-19481, and CVE-2019-19479.
  • gnutls added FIPS-related Diffie-Hellman and public-key validation checks for future certification requirements.
  • Identity Management, SSSD, Samba, and krb5 added support for the deprecated RC4 cipher through the DEFAULT:AD-SUPPORT crypto subpolicy for AD compatibility.
  • TSX is disabled by default in the kernel to improve security and reduce exposure to TAA mitigations.
  • USBGuard and fapolicyd now provide their own SELinux policies, improving confinement and security hardening.
  • Cyrus SASL added channel binding support for SASL/GSSAPI and SASL/GSS-SPNEGO to align with Microsoft LDAP channel binding requirements.

Bug Fixes

  • Anaconda fixes include improved SSH initial setup, correct SELinux labeling, valid /boot partition creation, and better handling of Kickstart and registration workflows.
  • DNF and microdnf fixes include correct GPG signature checking in dnf-automatic, improved reposync behavior, and plugin enable/disable support.
  • NetworkManager, firewalld, and nftables received multiple fixes for connection handling, ipset cleanup, and service interaction.
  • glibc fixes address loader crashes, memory handling issues, locale archive truncation, and several lookup and performance problems.
  • Virtualization fixes include more reliable VM migration, improved QEMU/libvirt logging and device support, and better handling of disk cache, CPU models, and guest features.
  • OpenSCAP and SCAP Security Guide fixes improve scanning, remediation generation, remote file handling, and memory usage on large systems.
  • fapolicyd fixes prevent updates from being blocked when running binaries are replaced during package updates.
  • ReaR fixes include rescue image creation with files larger than 4 GB on IBM POWER little endian and cleaner disk layout output.
  • Kernel fixes address kdump, entropy, BPF, memory hotplug, and several architecture-specific issues.

New Features

  • RHEL for Edge images with rpm-ostree, atomic upgrades, health checks, and rollback support.
  • Image Builder backend moved from lorax-composer to osbuild-composer with REST APIs and cloud image push support.
  • New module streams for nginx 1.18, Node.js 14, Perl 5.30, PHP 7.4, Ruby 2.7, and updated Git, Squid, and compiler toolsets.
  • Podman 2.0/2.1, Buildah, Skopeo, and related container tooling gained new APIs and capabilities.
  • New RHEL system roles for logging, TLOG session recording, NBDE client/server, metrics, and SAP automation.
  • GNOME kiosk single-application sessions and web console privilege switching were added.
  • Virtualization gained support for IBM Secure Execution, AMD EPYC Rome, new CPU models, and additional QEMU/libvirt features.
  • OpenJDK 11 and .NET 5 are now available on RHEL 8.

Known Issues

  • The CIS profile's rpm_verify_permissions rule does not work correctly.
  • The reboot --kexec and inst.kexec paths do not provide a predictable system state.
  • Image Builder upgrades from lorax-composer to osbuild-composer may not automatically preserve blueprints.
  • The installer may fail with self-signed HTTPS Kickstart sources unless inst.noverifyssl is used.
  • Some GUI installation and registration workflows can fail when unregistering too early or when using accounts that belong to multiple organizations.
  • SELinux disabled in /etc/selinux/config does not fully disable SELinux early enough and may cause memory leaks; use selinux=0 instead.
  • The rpm_verify_permissions rule in the CIS profile and some OSPP/CIS combinations with GUI package groups are incompatible.
  • OpenSSL FIPS mode accepts only compliant Diffie-Hellman parameter groups.
  • The podman system connection add command does not automatically set the first connection as default.
  • The udica tool is not expected to work with the container-tools:1.0 stream.

Hints

  • RHEL 8.3 is distributed with kernel 4.18.0-240.
  • To keep DNF behavior unchanged in custom configs, ensure best=True is set.
  • For AD compatibility with deprecated RC4, use update-crypto-policies --set DEFAULT:AD-SUPPORT.
  • To enable the new optimize-serial-console TuneD profile, use tuned-adm profile throughput-performance optimize-serial-console.
  • The nconnect NFS mount option supports multiple concurrent connections, up to 16.
  • The storage RHEL system role now supports ext4 and LVM resizing and swap management.
  • The authselect utility has a new minimal profile for local-only authentication setups.
  • The update-crypto-policies and fips-mode-setup scripts were moved to crypto-policies-scripts.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: 8.3

Vendor release date: Nov 3, 2020

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026