Views
12

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 8.10 introduces new application streams, container and system role enhancements, and kernel and security improvements. It also includes fixes for upgrade, networking, storage, and identity management issues.

Update Details

Security

  • OpenSSL adds API-level protections against Bleichenbacher-like attacks on RSA PKCS #1 v1.5 decryption, with mitigation for vulnerabilities such as CVE-2020-25659 and CVE-2020-25657.
  • SCAP Security Guide 0.1.72 updates CIS, PCI DSS 4.0, and DISA STIG profiles.
  • OpenSSH limits artificial authentication delays to reduce user enumeration risk.
  • DEP/NX support is added in GRUB and shim to harden the pre-boot stage.
  • Identity Management adds OAuth 2 device authorization support for external identity providers and Kerberos SSO.
  • SELinux policy updates add rules for ip vrf, sudo crontab, SSH login restrictions, and additional service access.
  • The sshd role now supports certificate-based SSH authentication.
  • The fapolicyd role and policy updates improve execution control and container compatibility.
  • The crypto-policies and NSS updates address deprecated or weak cryptographic behavior, including Camellia and SEED-related changes.
  • Git adds stricter ownership checks to mitigate CVE-2024-32004.

Bug Fixes

  • Installer accepts additional time zone definitions in Kickstart files.
  • NetworkManager mitigates TunnelVision impact in VPN profiles for CVE-2024-3661.
  • In-place upgrade improvements include better service-state detection, proxy support, local DNF repositories, and HTTPS repository handling.
  • ReaR fixes multiple recovery issues, including hybrid BIOS/UEFI boot detection, XFS mount option handling, thin pool metadata sizing, and rescue image bootability.
  • glibc fixes crashes and performance issues involving dlclose, wide-character writes, and ctype.h in multithreaded programs.
  • Samba, SSSD, and IdM include fixes for replica installation, ticket handling, logging, and authentication edge cases.
  • Multipath, dm-crypt, and dm-verity fixes address I/O queuing, NVMe fabric events, and memory corruption risks.
  • The ldconfig utility no longer crashes after interrupted upgrades.
  • The pcs utility fixes resource move, expired-constraint, and quorum-device validation behavior.
  • Podman and Container Tools receive fixes for secrets handling, rootless linger management, and database backend behavior.
  • The web console adds script generation and improved storage management.

New Features

  • Image Builder now supports partitioning modes and filesystem customization policies.
  • Python 3.12, Ruby 3.3, PHP 8.2, nginx 1.24, MariaDB 10.11, and PostgreSQL 16 are available as new application streams.
  • Identity Management now supports external IdP authentication using OAuth 2 Device Authorization Grant.
  • Podman adds containers.conf modules, SQLite as the default backend for new installs, HereDoc support in Containerfiles, and progress reporting in the REST API.
  • GCC Toolset 14, updated LLVM, Rust, Go, and GCC Toolset 13 components are included.
  • SGX and Intel IDXD move to full support.
  • New RHEL System Roles include bootloader, fapolicyd, snapshot management, and expanded networking, logging, and HA features.
  • Multi-FD VM migration is now supported.
  • The web console can generate Ansible and shell scripts and offers improved storage and virtualization workflows.

Known Issues

  • IBM Z installation may assign unpredictable RoCE interface names when net.naming-scheme=rhel-8.7 is ignored for FID-enumerated cards.
  • RHEL installation fails on IBM Power 10 systems with LPAR and secure boot enabled.
  • Anaconda running as an application can modify SELinux policy on the host system.
  • RHEL for Edge image creation has limitations with custom mount points for rpm-ostree payloads.
  • Some security profiles and tools have known limitations, including OpenSCAP memory usage, tailored profile handling, and certain SCAP rule incompatibilities.
  • Several virtualization, networking, and storage scenarios have documented limitations, including VM snapshot support, NVMe/TCP multipath, and specific hardware/firmware combinations.

Hints

  • RHEL 8.10 ships kernel 4.18.0-553.
  • For in-place upgrades from RHEL 7, supported paths include RHEL 7.9 to RHEL 8.8 or RHEL 8.10 on supported architectures.
  • The python3.12 stack is installed with yum install python3.12 and yum install python3.12-pip.
  • To install new module streams, use commands such as yum module install ruby:3.3, yum module install php:8.2, yum module install nginx:1.24, and yum module install postgresql:16.
  • Podman SQLite is the default backend for new RHEL 8.10 installations; upgraded systems keep BoltDB unless changed explicitly.
  • Several features are deprecated, including CNI networking, pasta as a network name, BoltDB backend, SPICE, and various older container and language streams.
  • Some changes require follow-up actions, such as updating sssd.conf, switching from SPICE to VNC for RHEL 9 migration, or using authselect/ansible-core instead of deprecated paths.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 8

Version: 4.18.0-553

Vendor release date: May 22, 2024

Original release notes: View on vendor site

Published on updatealert.io: Aug 8, 2026