Red Hat Enterprise Linux Server RHEL 8 Update Version RHEL 8.6 kernel 4.18.0-372
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 8.6 introduces major security, networking, storage, virtualization, and automation updates. It also includes new module streams such as PHP 8.0 and Perl 5.32, plus notable fixes and known issues for RHEL 8.6.
Update Details
Security
- OpenSSH servers now support drop-in configuration files via
Includeinsshd_config. - fapolicyd 1.1 adds new
rules.d/andtrust.d/directories and improves trust handling. - SELinux policy module verification is improved with
semodule -l --checksum. - Crypto policies now support
diffie-hellman-group14-sha256for libssh. - net-snmp-cert gencert now uses SHA512 by default instead of SHA1.
- OpenSCAP and SCAP Security Guide add multiple hardening and compliance improvements, including local file scanning,
faillock.confsupport, and updated STIG/CIS content. - Audit now includes sudoers monitoring in base rules and adds end-of-event timeout options.
- Identity Management now supports SHA384withRSA signing by default.
- The default
ssh_hash_known_hostsbehavior in SSSD now matches OpenSSH and is set to false. - eBPF is restricted to privileged users by default to reduce security risk from unprivileged BPF use.
- crypto-policies can now disable ChaCha20 in OpenSSL correctly.
- The
pam_cap.somodule now supportskeepcapsanddeferfor ambient capabilities.
Bug Fixes
- Image Builder can now create customized LVM filesystem layouts and resize partitions at runtime.
- rpm-ostree v2022.2 adds idempotent kernel argument handling and other compose/upgrade improvements.
- The
modulesynccommand is available to preserve modular metadata when redistributing modular repositories. - RPM adds a
--pathoption to query packages by path even when the file is not present. - NetworkManager 1.36.0 improves L3 handling, routing, WPA3, bridge behavior, and DHCP robustness.
- Samba 4.15.5 updates utility behavior and enables server multi-channel support by default.
- Directory Server 1.4.3.28 improves replica stability, connection handling, and ACI performance.
- The
-jflag now works correctly in Makefiles when set inMAKEFLAGS. pthread_once()in glibc no longer hangs when C++ exceptions are thrown.xfsrestorenow restores backups correctly without creating orphanage files in the reported scenario.- ReaR now handles unused LVM physical volumes and multipath exclusions correctly.
- Kdump works correctly on some KVM guests using the default memory size.
- The
dmidecode --type 17command now decodes DDR5 memory information correctly. - The
multipathd.socketunit no longer disables multipathd after repeated failed starts. - The
NetworkManagerstatic IPv4 address is now treated as primary when used with DHCP in the same profile.
New Features
- PHP 8.0 is available as a new module stream.
- Perl 5.32 is available as a new module stream.
- GCC Toolset 11, LLVM Toolset 13.0.1, Rust Toolset 1.58.1, and Go Toolset 1.17.7 are updated.
- A new
log4j:2module is available in AppStream. - The
hostapdpackage is now included for supported 802.1X authenticator use cases. - The
firewallRHEL system role is now available. - The HA Cluster system role is now fully supported.
- Podman 4.0 and the
container-tools:4.0stream are available. - The Netavark network stack is available for containers.
- RHEL for Edge gains built-in Greenboot health checks by default.
- Windows 11 and Windows Server 2022 guests are supported.
- The
rigmonitoring utility is newly available.
Known Issues
- Installation fails on IBM Power 10 systems with LPAR and secure boot enabled.
- Anaconda running as an application on an installed system can modify SELinux policy unexpectedly.
- The
authandauthconfigKickstart commands require the AppStream repository. - Network access is not enabled by default in the installation program.
- A security DNF upgrade can skip obsoleted packages when using security filters.
- The
nm-cloud-setupservice can remove manually configured secondary IP addresses. - RHEL 8.6 guest VMs may show reduced network performance in some cases.
- Live migration to a RHEL 8.6 Intel host can fail from earlier RHEL 8 minor versions due to TSX deprecation.
- Using many virtio-blk disks can exhaust interrupt vectors and prevent VM boot.
- The
redhat-support-toolutility does not work with the FUTURE crypto policy. - Running systemd inside older container images such as
centos:7does not work without workarounds. - Container images signed with a Beta GPG key cannot be pulled by default.
Hints
- RHEL 8.6 is distributed with kernel
4.18.0-372. - Supported in-place upgrade paths from RHEL 7 to RHEL 8.6 are explicitly listed; do not assume all RHEL 7 systems can upgrade directly.
- For Ansible-based automation, RHEL 8.6 introduces
ansible-coreand deprecates Ansible Engine; users must migrate manually. - The
subscription-manager syspurposesubcommand replaces older system purpose commands. - Several Samba command-line options were renamed or removed; review scripts after upgrading.
- RHEL 8.6 is compatible with certain RHEL 9 XFS images only when
bigtimeandinobtcountare enabled. - The
fapolicyd.rulesfile is deprecated in favor of/etc/fapolicyd/rules.d/. - TLS 1.0 and TLS 1.1 are deprecated and disabled by default in the DEFAULT crypto policy; use LEGACY only if required.
- The
openssh-ldappackage is deprecated; Red Hat recommends SSSD andsss_ssh_authorizedkeys. - The
network-scriptspackage is deprecated and not installed by default. - Red Hat recommends migrating from
virt-managerand SPICE to supported alternatives over time.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 8
Version: RHEL 8.6 kernel 4.18.0-372
Vendor release date: May 10, 2022
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026