Views
13

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.6 introduces major security, networking, storage, virtualization, and automation updates. It also includes new module streams such as PHP 8.0 and Perl 5.32, plus notable fixes and known issues for RHEL 8.6.

Update Details

Security

  • OpenSSH servers now support drop-in configuration files via Include in sshd_config.
  • fapolicyd 1.1 adds new rules.d/ and trust.d/ directories and improves trust handling.
  • SELinux policy module verification is improved with semodule -l --checksum.
  • Crypto policies now support diffie-hellman-group14-sha256 for libssh.
  • net-snmp-cert gencert now uses SHA512 by default instead of SHA1.
  • OpenSCAP and SCAP Security Guide add multiple hardening and compliance improvements, including local file scanning, faillock.conf support, and updated STIG/CIS content.
  • Audit now includes sudoers monitoring in base rules and adds end-of-event timeout options.
  • Identity Management now supports SHA384withRSA signing by default.
  • The default ssh_hash_known_hosts behavior in SSSD now matches OpenSSH and is set to false.
  • eBPF is restricted to privileged users by default to reduce security risk from unprivileged BPF use.
  • crypto-policies can now disable ChaCha20 in OpenSSL correctly.
  • The pam_cap.so module now supports keepcaps and defer for ambient capabilities.

Bug Fixes

  • Image Builder can now create customized LVM filesystem layouts and resize partitions at runtime.
  • rpm-ostree v2022.2 adds idempotent kernel argument handling and other compose/upgrade improvements.
  • The modulesync command is available to preserve modular metadata when redistributing modular repositories.
  • RPM adds a --path option to query packages by path even when the file is not present.
  • NetworkManager 1.36.0 improves L3 handling, routing, WPA3, bridge behavior, and DHCP robustness.
  • Samba 4.15.5 updates utility behavior and enables server multi-channel support by default.
  • Directory Server 1.4.3.28 improves replica stability, connection handling, and ACI performance.
  • The -j flag now works correctly in Makefiles when set in MAKEFLAGS.
  • pthread_once() in glibc no longer hangs when C++ exceptions are thrown.
  • xfsrestore now restores backups correctly without creating orphanage files in the reported scenario.
  • ReaR now handles unused LVM physical volumes and multipath exclusions correctly.
  • Kdump works correctly on some KVM guests using the default memory size.
  • The dmidecode --type 17 command now decodes DDR5 memory information correctly.
  • The multipathd.socket unit no longer disables multipathd after repeated failed starts.
  • The NetworkManager static IPv4 address is now treated as primary when used with DHCP in the same profile.

New Features

  • PHP 8.0 is available as a new module stream.
  • Perl 5.32 is available as a new module stream.
  • GCC Toolset 11, LLVM Toolset 13.0.1, Rust Toolset 1.58.1, and Go Toolset 1.17.7 are updated.
  • A new log4j:2 module is available in AppStream.
  • The hostapd package is now included for supported 802.1X authenticator use cases.
  • The firewall RHEL system role is now available.
  • The HA Cluster system role is now fully supported.
  • Podman 4.0 and the container-tools:4.0 stream are available.
  • The Netavark network stack is available for containers.
  • RHEL for Edge gains built-in Greenboot health checks by default.
  • Windows 11 and Windows Server 2022 guests are supported.
  • The rig monitoring utility is newly available.

Known Issues

  • Installation fails on IBM Power 10 systems with LPAR and secure boot enabled.
  • Anaconda running as an application on an installed system can modify SELinux policy unexpectedly.
  • The auth and authconfig Kickstart commands require the AppStream repository.
  • Network access is not enabled by default in the installation program.
  • A security DNF upgrade can skip obsoleted packages when using security filters.
  • The nm-cloud-setup service can remove manually configured secondary IP addresses.
  • RHEL 8.6 guest VMs may show reduced network performance in some cases.
  • Live migration to a RHEL 8.6 Intel host can fail from earlier RHEL 8 minor versions due to TSX deprecation.
  • Using many virtio-blk disks can exhaust interrupt vectors and prevent VM boot.
  • The redhat-support-tool utility does not work with the FUTURE crypto policy.
  • Running systemd inside older container images such as centos:7 does not work without workarounds.
  • Container images signed with a Beta GPG key cannot be pulled by default.

Hints

  • RHEL 8.6 is distributed with kernel 4.18.0-372.
  • Supported in-place upgrade paths from RHEL 7 to RHEL 8.6 are explicitly listed; do not assume all RHEL 7 systems can upgrade directly.
  • For Ansible-based automation, RHEL 8.6 introduces ansible-core and deprecates Ansible Engine; users must migrate manually.
  • The subscription-manager syspurpose subcommand replaces older system purpose commands.
  • Several Samba command-line options were renamed or removed; review scripts after upgrading.
  • RHEL 8.6 is compatible with certain RHEL 9 XFS images only when bigtime and inobtcount are enabled.
  • The fapolicyd.rules file is deprecated in favor of /etc/fapolicyd/rules.d/.
  • TLS 1.0 and TLS 1.1 are deprecated and disabled by default in the DEFAULT crypto policy; use LEGACY only if required.
  • The openssh-ldap package is deprecated; Red Hat recommends SSSD and sss_ssh_authorizedkeys.
  • The network-scripts package is deprecated and not installed by default.
  • Red Hat recommends migrating from virt-manager and SPICE to supported alternatives over time.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: RHEL 8.6 kernel 4.18.0-372

Vendor release date: May 10, 2022

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026