Red Hat Enterprise Linux Server RHEL 8 Update Version 8.3
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 8.3 adds RHEL for Edge, updated installer and Image Builder workflows, new module streams, and major security/compliance updates. It also includes kernel, networking, virtualization, storage, and identity management enhancements for RHEL 8.3. Reference IDs: RHBA-2021:0569, RHEA-2020:5101.
Update Details
Security
- OpenSCAP, SCAP Security Guide, and related compliance content were updated, including new CIS RHEL 8, CIS RHEL 7, HIPAA, and NIST-800-171 profiles.
- libssh was rebased to 0.9.4 and fixes CVE-2019-14889 and CVE-2020-1730.
- OpenSC was rebased to 0.20.0 and fixes CVE-2019-6502, CVE-2019-15946, CVE-2019-15945, CVE-2019-19480, CVE-2019-19481, and CVE-2019-19479.
- gnutls added FIPS-related Diffie-Hellman and public-key validation checks for future certification requirements.
- Identity Management, SSSD, Samba, and krb5 added support for the deprecated RC4 cipher through the
DEFAULT:AD-SUPPORTcrypto subpolicy for AD compatibility. - TSX is disabled by default in the kernel to improve security and reduce exposure to TAA mitigations.
- USBGuard and fapolicyd now provide their own SELinux policies, improving confinement and security hardening.
- Cyrus SASL added channel binding support for SASL/GSSAPI and SASL/GSS-SPNEGO to align with Microsoft LDAP channel binding requirements.
Bug Fixes
- Anaconda fixes include improved SSH initial setup, correct SELinux labeling, valid /boot partition creation, and better handling of Kickstart and registration workflows.
- DNF and microdnf fixes include correct GPG signature checking in dnf-automatic, improved reposync behavior, and plugin enable/disable support.
- NetworkManager, firewalld, and nftables received multiple fixes for connection handling, ipset cleanup, and service interaction.
- glibc fixes address loader crashes, memory handling issues, locale archive truncation, and several lookup and performance problems.
- Virtualization fixes include more reliable VM migration, improved QEMU/libvirt logging and device support, and better handling of disk cache, CPU models, and guest features.
- OpenSCAP and SCAP Security Guide fixes improve scanning, remediation generation, remote file handling, and memory usage on large systems.
- fapolicyd fixes prevent updates from being blocked when running binaries are replaced during package updates.
- ReaR fixes include rescue image creation with files larger than 4 GB on IBM POWER little endian and cleaner disk layout output.
- Kernel fixes address kdump, entropy, BPF, memory hotplug, and several architecture-specific issues.
New Features
- RHEL for Edge images with rpm-ostree, atomic upgrades, health checks, and rollback support.
- Image Builder backend moved from
lorax-composertoosbuild-composerwith REST APIs and cloud image push support. - New module streams for nginx 1.18, Node.js 14, Perl 5.30, PHP 7.4, Ruby 2.7, and updated Git, Squid, and compiler toolsets.
- Podman 2.0/2.1, Buildah, Skopeo, and related container tooling gained new APIs and capabilities.
- New RHEL system roles for logging, TLOG session recording, NBDE client/server, metrics, and SAP automation.
- GNOME kiosk single-application sessions and web console privilege switching were added.
- Virtualization gained support for IBM Secure Execution, AMD EPYC Rome, new CPU models, and additional QEMU/libvirt features.
- OpenJDK 11 and .NET 5 are now available on RHEL 8.
Known Issues
- The CIS profile's
rpm_verify_permissionsrule does not work correctly. - The
reboot --kexecandinst.kexecpaths do not provide a predictable system state. - Image Builder upgrades from
lorax-composertoosbuild-composermay not automatically preserve blueprints. - The installer may fail with self-signed HTTPS Kickstart sources unless
inst.noverifysslis used. - Some GUI installation and registration workflows can fail when unregistering too early or when using accounts that belong to multiple organizations.
- SELinux
disabledin/etc/selinux/configdoes not fully disable SELinux early enough and may cause memory leaks; useselinux=0instead. - The
rpm_verify_permissionsrule in the CIS profile and some OSPP/CIS combinations with GUI package groups are incompatible. - OpenSSL FIPS mode accepts only compliant Diffie-Hellman parameter groups.
- The
podman system connection addcommand does not automatically set the first connection as default. - The
udicatool is not expected to work with thecontainer-tools:1.0stream.
Hints
- RHEL 8.3 is distributed with kernel
4.18.0-240. - To keep DNF behavior unchanged in custom configs, ensure
best=Trueis set. - For AD compatibility with deprecated RC4, use
update-crypto-policies --set DEFAULT:AD-SUPPORT. - To enable the new
optimize-serial-consoleTuneD profile, usetuned-adm profile throughput-performance optimize-serial-console. - The
nconnectNFS mount option supports multiple concurrent connections, up to 16. - The
storageRHEL system role now supports ext4 and LVM resizing and swap management. - The
authselectutility has a new minimal profile for local-only authentication setups. - The
update-crypto-policiesandfips-mode-setupscripts were moved tocrypto-policies-scripts.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 8
Version: 8.3
Vendor release date: Nov 3, 2020
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026