Views
16

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.4 release notes cover major security, networking, kernel, storage, and application stream updates for RHEL 8.4. They also document known issues, deprecations, and technology previews for the release.

Update Details

Security

  • Libreswan 4.3 adds IPsec VPN over TCP encapsulation and IKEv2 labeled IPsec support.
  • SCAP Security Guide 0.1.54 and OpenSCAP 1.3.4 add updated hardening profiles, memory fixes, and improved compliance coverage.
  • fapolicyd adds integrity checking and an RPM plugin that tracks YUM and RPM transactions.
  • p11-kit 0.23.19 fixes CVE-2020-29361, CVE-2020-29362, and CVE-2020-29363.
  • ghostscript-9.27 includes fixes for CVE-2020-14373 and CVE-2020-16287 through CVE-2020-16310, plus CVE-2020-17538.
  • Samba 4.13.2 addresses CVE-2020-1472 and updates FIPS-related authentication behavior.
  • IdM adds support for cross-forest trust in FIPS mode and new password policy options.
  • USBGuard 1.0.0-1 improves policy handling and audit messaging.
  • SELinux and fapolicyd fixes improve policy correctness, labeling behavior, and update reliability.

Bug Fixes

  • Anaconda fixes boot device NVRAM handling, graphical KVM installation on IBM Z, deprecated boot argument warnings, and several partitioning and network-installation issues.
  • DNF and createrepo_c add transaction replay, cache-based repo loading, modular metadata handling, and protect_running_kernel control.
  • NetworkManager 1.30.0 adds DHCP and hostname handling improvements, WPA3 Enterprise Suite-B support, and better initrd generation.
  • Kernel fixes include proactive compaction, slab controller improvements, time namespaces, EDAC support, live patch subscription, and multiple crash and memory-reclaim fixes.
  • Storage and filesystem fixes include Stratis symlink migration, DAX mount controls, SMB Direct support, NFS and SMB reliability improvements, and new mount API syscalls.
  • High availability updates add new Pacemaker rule types, colocation influence control, cluster config commands, and encrypted Corosync configuration changes.
  • Identity Management fixes include dsidm rename/move support, improved AD site discovery, SSSD domain enablement controls, and Directory Server logging and indexing improvements.
  • Virtualization fixes include better Hyper-V console performance, multi-monitor Wayland support with QXL, and improved AMD EPYC and Intel CPU model support.
  • Container fixes include default connection handling in Podman and rootless --pid=host support.

New Features

  • Nmstate is fully supported for declarative host networking.
  • Python 3.9, SWIG 4.0, Subversion 1.14, Redis 6, PostgreSQL 13, MariaDB 10.5, and OpenJDK 11 are available as new module streams or updates.
  • The kpatch-dnf plugin enables kernel live patch subscriptions.
  • The time namespace feature is available for container clock isolation.
  • The rhel8-tang container image is available for Clevis/Tang decryption support.
  • The rhc Red Hat connector CLI is available as a Technology Preview.
  • RHEL system roles gain SSH client/server, crypto policy, logging, metrics, and collection-format support.
  • Podman adds Docker volume plugin support, secure short-name handling, and auto-update support.
  • The web console adds restart checks, performance analysis, and SSH key setup assistance.

Known Issues

  • The auth and authconfig Kickstart commands require the AppStream repository.
  • Using reboot --kexec or inst.kexec does not provide a predictable system state.
  • Network access is not enabled by default in the installer.
  • The osbuild-composer backend does not automatically replicate lorax-composer blueprints during upgrade.
  • RHEL for Edge installation fails if the same username is defined in both blueprint and Kickstart files.
  • Pacemaker shutdown behavior can affect resource agents that parse crm_mon output, including ocf:heartbeat:pgsql.
  • Libreswan has known issues with leftikeport/rightikeport and multiple labeled IPsec connections under IKEv2.
  • SELinux disabled in /etc/selinux/config does not fully disable SELinux at boot and may cause memory leaks.
  • Several virtualization, cloud, and storage scenarios have unresolved issues, including kdump on Azure/Hyper-V, virtiofs with mixed guest/policy versions, and LVM or NFS limitations.

Hints

  • RHEL 8.4 ships kernel 4.18.0-305.
  • For Python urllib parsing, the default separator changes to & only to mitigate CVE-2021-23336.
  • Clevis no longer automatically adds rd.neednet=1; use --hostonly-cmdline or hostonly_cmdline=yes if needed.
  • Stratis filesystem symlinks moved from /stratis/... to /dev/stratis/...; update mounts and scripts accordingly.
  • The default nsslapd-nagle setting is now off in Directory Server.
  • NFSv3 over UDP is disabled.
  • TLS 1.0 and TLS 1.1 are deprecated; use update-crypto-policies --set LEGACY only if required.
  • The kabi_whitelist package was renamed to kabi_stablelist.
  • The network-scripts package is deprecated; NetworkManager is the supported path.
  • For Samba, Red Hat recommends avoiding the insecure wide links feature and using bind mounts instead.

Links

  • RHEL 8.4 release notes
    https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/index

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: 8.4

Vendor release date: May 18, 2021

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026