Views
16

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.8 adds major updates across installer, security, containers, networking, and development tools. It includes FIPS 140-3-aligned kernel settings, Python 3.11, PostgreSQL 15, nginx 1.22, and numerous bug fixes and known issues.

Update Details

Security

  • FIPS mode settings were adjusted to align with FIPS 140-3, disabling several algorithms and tightening cryptographic requirements.
  • Libreswan was rebased to 4.9, adding IPsec and authentication improvements.
  • fapolicyd can now filter the RPM database through rpm-filter.conf.
  • OpenSCAP was rebased to 1.3.7 with security compliance fixes.
  • Rsyslog TLS logging now supports multiple CA files for certificate chains.
  • systemd-socket-proxyd now runs in its own SELinux domain.
  • Node.js 18.14 / npm 9 removes unscoped authentication settings for security reasons.
  • glibc added SafeLinking to improve malloc hardening.
  • OpenSSL in FIPS mode enforces stricter D-H parameter requirements.
  • SELinux policy updates improve confinement for services such as udftools, insights-client, samba-dcerpcd, vlock, and ipmitool.
  • SCAP Security Guide and STIG profiles were updated, including new and revised security rules.
  • crypto-policies now disable NSEC3DSA for BIND and fix Camellia handling.
  • Go Toolset 1.19.4 includes security fixes in crypto/tls, mime/multipart, net/http, and path/filepath.

Bug Fixes

  • Installer fixes for custom partitioning, yum repo option handling, kickstart filename DHCP handling, and GPT layout creation.
  • RPM and DNF fixes for fapolicyd restarts, security-filtered upgrades, rollback of package groups/environments, and RPM archive handling.
  • NetworkManager fixes for cloud-setup address preservation, bond activation, DHCPv6 handling, and /etc/resolv.conf updates.
  • ReaR fixes for IBM Z recovery, excluded DASDs, and non-LVM XFS restoration.
  • rsync now handles extended attributes with regular-expression filters correctly.
  • OpenSCAP and SCAP Security Guide fixes for STIG/CIS profile alignment, idle session rules, and audit rule handling.
  • Samba, SSSD, IdM, and authselect fixes for authentication, trust, and policy behavior.
  • KVM and virtualization fixes for nested VM timekeeping, network performance, memfd guests, and VM boot issues.
  • Kernel and driver fixes for VMD, VDO, kpatch, and several hardware platforms.
  • System roles fixes for firewall/SELinux integration, quorum devices, SBD behavior, and secret handling.

New Features

  • Image Builder web console now provides a unified blueprint and image management experience.
  • RHEL for Edge simplified-installer images now support specifying a user in the blueprint.
  • New yum offline-upgrade command supports offline updates and advisory filtering.
  • ReaR is now fully supported on 64-bit IBM Z.
  • New synce4l package adds SyncE frequency synchronization support.
  • TuneD 2.20.0 adds runtime device movement and new CPU tuning features.
  • Python 3.11 is available as standard RPM packages.
  • nginx 1.22, PostgreSQL 15, Git 2.39.1, Git LFS 3.2.0, Tomcat 9, and SWIG 4.1 are introduced or rebased.
  • Podman, sigstore, Toolbox, and Netavark/Aardvark enhancements expand container support.
  • New RHEL system roles include ad_integration, rhc, and journald.
  • Web console adds NBDE binding improvements and crypto subpolicy selection.
  • RHEL 8.8 kernel includes new drivers, Secure Execution guest dump encryption, and updated networking behavior.

Known Issues

  • IBM Z RoCE cards may receive unpredictable interface names during installation.
  • RHEL installation fails on IBM Power 10 systems with LPAR and secure boot enabled.
  • Anaconda running as an application can modify SELinux policy on the host system.
  • Network access is not enabled by default in the installer.
  • Several storage, kernel, virtualization, cloud-init, and graphics issues remain unresolved, including VDO, kdump, Hyper-V, and installer black-screen problems.

Hints

  • RHEL 8.8 is distributed with kernel version 4.18.0-477.10.
  • In-place upgrade paths from RHEL 7.9 to RHEL 8.8 are supported on selected architectures.
  • Python 3.11 is installed as standard RPM packages and can run in parallel with earlier Python versions.
  • For PostgreSQL 15, the public schema permissions changed and applications may need updates for PQsendQuery() pipeline mode usage.
  • The container-tools:3.0 module stream and CNI network stack are deprecated; Netavark is the recommended direction.
  • The --token option of subscription-manager register is deprecated.
  • Several Kickstart commands and options are deprecated, including authconfig, device, lilo, reboot --kexec, and ignoredisk --interactive.
  • The SELINUX=disabled setting in /etc/selinux/config is deprecated; use selinux=0 on the kernel command line to fully disable SELinux.
  • The openssh-ldap package, Ansible Engine, virt-manager, and xinetd are deprecated.
  • For RHEL system roles, some roles now support firewall, SELinux, and certificate role integration.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: RHEL 8.8 kernel 4.18.0-477.10

Vendor release date: May 16, 2023

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026