Red Hat Enterprise Linux Server RHEL 8 Update Version 8.4
Views
16
Your rating
Rate update installation process
Log in to rate this update.
Login
Risk factor
No ratings yet. Be the first to rate this update.
Smooth installs
0%
Minor issues
0%
Major issues
0%
AI enhanced content
Update Summary
Red Hat Enterprise Linux 8.4 release notes cover major security, networking, kernel, storage, and application stream updates for RHEL 8.4. They also document known issues, deprecations, and technology previews for the release.
Update Details
Security
- Libreswan 4.3 adds IPsec VPN over TCP encapsulation and IKEv2 labeled IPsec support.
- SCAP Security Guide 0.1.54 and OpenSCAP 1.3.4 add updated hardening profiles, memory fixes, and improved compliance coverage.
- fapolicyd adds integrity checking and an RPM plugin that tracks YUM and RPM transactions.
- p11-kit 0.23.19 fixes CVE-2020-29361, CVE-2020-29362, and CVE-2020-29363.
- ghostscript-9.27 includes fixes for CVE-2020-14373 and CVE-2020-16287 through CVE-2020-16310, plus CVE-2020-17538.
- Samba 4.13.2 addresses CVE-2020-1472 and updates FIPS-related authentication behavior.
- IdM adds support for cross-forest trust in FIPS mode and new password policy options.
- USBGuard 1.0.0-1 improves policy handling and audit messaging.
- SELinux and fapolicyd fixes improve policy correctness, labeling behavior, and update reliability.
Bug Fixes
- Anaconda fixes boot device NVRAM handling, graphical KVM installation on IBM Z, deprecated boot argument warnings, and several partitioning and network-installation issues.
- DNF and createrepo_c add transaction replay, cache-based repo loading, modular metadata handling, and protect_running_kernel control.
- NetworkManager 1.30.0 adds DHCP and hostname handling improvements, WPA3 Enterprise Suite-B support, and better initrd generation.
- Kernel fixes include proactive compaction, slab controller improvements, time namespaces, EDAC support, live patch subscription, and multiple crash and memory-reclaim fixes.
- Storage and filesystem fixes include Stratis symlink migration, DAX mount controls, SMB Direct support, NFS and SMB reliability improvements, and new mount API syscalls.
- High availability updates add new Pacemaker rule types, colocation influence control, cluster config commands, and encrypted Corosync configuration changes.
- Identity Management fixes include dsidm rename/move support, improved AD site discovery, SSSD domain enablement controls, and Directory Server logging and indexing improvements.
- Virtualization fixes include better Hyper-V console performance, multi-monitor Wayland support with QXL, and improved AMD EPYC and Intel CPU model support.
- Container fixes include default connection handling in Podman and rootless
--pid=hostsupport.
New Features
- Nmstate is fully supported for declarative host networking.
- Python 3.9, SWIG 4.0, Subversion 1.14, Redis 6, PostgreSQL 13, MariaDB 10.5, and OpenJDK 11 are available as new module streams or updates.
- The
kpatch-dnfplugin enables kernel live patch subscriptions. - The
time namespacefeature is available for container clock isolation. - The
rhel8-tangcontainer image is available for Clevis/Tang decryption support. - The
rhcRed Hat connector CLI is available as a Technology Preview. - RHEL system roles gain SSH client/server, crypto policy, logging, metrics, and collection-format support.
- Podman adds Docker volume plugin support, secure short-name handling, and auto-update support.
- The web console adds restart checks, performance analysis, and SSH key setup assistance.
Known Issues
- The
authandauthconfigKickstart commands require the AppStream repository. - Using
reboot --kexecorinst.kexecdoes not provide a predictable system state. - Network access is not enabled by default in the installer.
- The osbuild-composer backend does not automatically replicate lorax-composer blueprints during upgrade.
- RHEL for Edge installation fails if the same username is defined in both blueprint and Kickstart files.
- Pacemaker shutdown behavior can affect resource agents that parse
crm_monoutput, includingocf:heartbeat:pgsql. - Libreswan has known issues with
leftikeport/rightikeportand multiple labeled IPsec connections under IKEv2. - SELinux
disabledin/etc/selinux/configdoes not fully disable SELinux at boot and may cause memory leaks. - Several virtualization, cloud, and storage scenarios have unresolved issues, including kdump on Azure/Hyper-V, virtiofs with mixed guest/policy versions, and LVM or NFS limitations.
Hints
- RHEL 8.4 ships kernel
4.18.0-305. - For Python urllib parsing, the default separator changes to
&only to mitigate CVE-2021-23336. - Clevis no longer automatically adds
rd.neednet=1; use--hostonly-cmdlineorhostonly_cmdline=yesif needed. - Stratis filesystem symlinks moved from
/stratis/...to/dev/stratis/...; update mounts and scripts accordingly. - The default
nsslapd-naglesetting is now off in Directory Server. - NFSv3 over UDP is disabled.
- TLS 1.0 and TLS 1.1 are deprecated; use
update-crypto-policies --set LEGACYonly if required. - The
kabi_whitelistpackage was renamed tokabi_stablelist. - The
network-scriptspackage is deprecated; NetworkManager is the supported path. - For Samba, Red Hat recommends avoiding the insecure wide links feature and using bind mounts instead.
Links
-
RHEL 8.4 release notes
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/index
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 8
Version: 8.4
Vendor release date: May 18, 2021
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026