Views
12

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.9 adds major updates across security, networking, containers, development tools, and system roles. It also includes kernel 4.18.0-513.5.1, new features such as Node.js 20 and GCC Toolset 13, plus notable bug fixes and known issues.

Update Details

Security

  • OpenSCAP rebased to 1.3.8 and SCAP Security Guide rebased to 0.1.69 with updated ANSSI-BP-028 profiles, improved interactive user rules, and DISA STIG support for audit_rules_login_events_faillock.
  • opencryptoki rebased to 3.21.0 with security hardening; pkcsslotd no longer runs as root.
  • fapolicyd now reports rule numbers for denials, improving troubleshooting and policy enforcement.
  • The default nftables configuration adds a do_masquerade chain to reduce port shadow attack risk described in CVE-2021-3773.
  • NetworkManager supports the no-aaaa DNS option to suppress AAAA queries.
  • Python tarfile extraction now uses a safer default filter to mitigate CVE-2007-4559 directory traversal.
  • HTTP::Tiny verifies TLS certificates by default, fixing CVE-2023-31486 and CVE-2023-31484.
  • Python adds PYTHON_EMAIL_DISABLE_STRICT_ADDR_PARSING to mitigate CVE-2023-27043.
  • crypto-policies updates permitted_enctypes behavior to avoid FIPS replication issues and restricts weaker Kerberos encryption types.
  • SELinux adds virt_qemu_ga_run_unconfined to allow confined QEMU Guest Agent commands without AVC denials.
  • The virtiofsd killpriv_v2 behavior may leave SUID/SGID bits uncleared; disable it with -o no_killpriv_v2 if needed.
  • The fapolicyd trusted database update issue was fixed so removed programs can no longer execute.
  • The microsoft.sql.server role no longer creates AD-based SQL Server logins, reducing exposure of privileged accounts.

Bug Fixes

  • Installer liveimg --noverifyssl now correctly skips certificate validation for HTTPS downloads.
  • Booting from NFS with SELinux enforcing now works correctly.
  • YUM needs-restarting -s now handles non-systemd or broken processes more gracefully.
  • DNF automatic updates now report transaction failures correctly.
  • The which command no longer fails on very long paths.
  • grubby now passes kernel arguments correctly when adding a new kernel.
  • Multipath persistent reservation keys are now applied to all paths.
  • Pacemaker and pcs fixes improve colocation handling, DC elections, bundle moves, and SCSI device updates.
  • SSSD and Directory Server fixes improve GPO access control, duplicate attribute handling, connection table sizing, and paged search performance.
  • Samba, IPA, and Kerberos fixes improve SMB performance, trust handling, and certificate/IDM behavior.
  • Cloud-init, kdump, ReaR, and virtualization fixes address boot, provisioning, and VM hotplug issues.
  • Several system roles were fixed for firewall, kdump, storage, podman, certificate, and systemd management workflows.

New Features

  • AWS EC2 AMD/Intel 64-bit AMI images now support UEFI boot in addition to legacy BIOS boot.
  • New boot option inst.wait_for_disks= lets installers wait longer for kickstart files or kernel drivers.
  • New kickstart DNS options allow manual DNS search domains and ignoring DHCP-provided DNS settings.
  • Node.js 20 is now fully supported as module stream nodejs:20.
  • GCC Toolset 13 is now available, including GCC 13.1.1, GDB 12.1, binutils 2.40, dwz 0.14, and annobin 12.20.
  • LLVM Toolset 16.0.6, Rust Toolset 1.71.1, Go Toolset 1.20.10, Grafana 9.2.10, and grafana-pcp 5.1.1 were updated.
  • .NET 8.0 is available with C# 12, F# 8, and container image build support.
  • Postfix now supports SRV lookups.
  • vsftpd can now configure TLS 1.3 cipher suites.
  • Pacemaker and RHEL system roles gained new capabilities, including policy-based routing, SNMPv3 alerts, Quadlets, secrets, systemd unit management, and additional firewall/storage options.

Known Issues

  • IBM Z installation may assign unpredictable RoCE interface names for FID-enumerated cards.
  • RHEL installation on IBM Power 10 with LPAR and secure boot enabled fails.
  • Anaconda running as an application can alter SELinux policy on the host system.
  • The auth and authconfig Kickstart commands require the AppStream repository.
  • RHEL for Edge rpm-ostree installations may fail to create some custom mount points.
  • Image Builder with STIG remediation can fail to boot with a FIPS error.
  • The sshd -T output may not reflect system-wide crypto policy settings.
  • OpenSCAP and SCAP remediations have several limitations, including memory consumption issues and some rules that are not applicable or inaccurate in specific scenarios.
  • The fapolicyd utility can incorrectly allow execution of changed files in some cases.
  • Some Rsyslog priority strings do not work correctly.
  • IdM and FIPS mode have several trust and encryption limitations, including cross-forest trust and Vault encryption issues.
  • Several virtualization issues remain, including VM boot, migration, vTPM queue limits, and device passthrough limitations.
  • Cloud-init on VMware and Azure has known boot and networking limitations in some scenarios.

Hints

  • To install nodejs:20, run yum module install nodejs:20.
  • To install GCC Toolset 13, run yum install gcc-toolset-13 and use scl enable gcc-toolset-13 ....
  • For in-place upgrades from RHEL 7, supported paths include RHEL 8.6, 8.8, and 8.9 on supported architectures.
  • RHEL 8.9 uses kernel version 4.18.0-513.5.1.
  • OpenJDK packages in RHEL 8.9 share binaries with portable Linux releases, changing the rebuild process from SRPM.
  • For FIPS or crypto-policy changes, review /etc/crypto-policies/back-ends/krb5.config and custom subpolicies if Kerberos is used.
  • Some system roles now require or support new parameters, such as ssh_backup, firewall_disable_conflicting_services, ipaserver_random_serial_numbers, and mount_user/mount_group/mount_permissions.
  • Podman Quadlets work only with rootful containers on RHEL 8.
  • The podman SQLite backend requires podman system reset and recreation of containers and pods.
  • Several deprecated items are called out for migration planning, including network-scripts, openssh-ldap, xinetd, ABRT, libdwarf, and older container-tools streams.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: kernel 4.18.0-513.5.1

Vendor release date: Nov 14, 2023

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026