Red Hat Enterprise Linux Server RHEL 8 Update Version 4.18.0-553
Views
12
Your rating
Rate update installation process
Log in to rate this update.
Login
Risk factor
No ratings yet. Be the first to rate this update.
Smooth installs
0%
Minor issues
0%
Major issues
0%
AI enhanced content
Update Summary
Red Hat Enterprise Linux 8.10 introduces new application streams, container and system role enhancements, and kernel and security improvements. It also includes fixes for upgrade, networking, storage, and identity management issues.
Update Details
Security
- OpenSSL adds API-level protections against Bleichenbacher-like attacks on RSA PKCS #1 v1.5 decryption, with mitigation for vulnerabilities such as CVE-2020-25659 and CVE-2020-25657.
- SCAP Security Guide 0.1.72 updates CIS, PCI DSS 4.0, and DISA STIG profiles.
- OpenSSH limits artificial authentication delays to reduce user enumeration risk.
- DEP/NX support is added in GRUB and shim to harden the pre-boot stage.
- Identity Management adds OAuth 2 device authorization support for external identity providers and Kerberos SSO.
- SELinux policy updates add rules for
ip vrf,sudo crontab, SSH login restrictions, and additional service access. - The
sshdrole now supports certificate-based SSH authentication. - The
fapolicydrole and policy updates improve execution control and container compatibility. - The
crypto-policiesand NSS updates address deprecated or weak cryptographic behavior, including Camellia and SEED-related changes. - Git adds stricter ownership checks to mitigate CVE-2024-32004.
Bug Fixes
- Installer accepts additional time zone definitions in Kickstart files.
- NetworkManager mitigates TunnelVision impact in VPN profiles for CVE-2024-3661.
- In-place upgrade improvements include better service-state detection, proxy support, local DNF repositories, and HTTPS repository handling.
- ReaR fixes multiple recovery issues, including hybrid BIOS/UEFI boot detection, XFS mount option handling, thin pool metadata sizing, and rescue image bootability.
- glibc fixes crashes and performance issues involving
dlclose, wide-character writes, andctype.hin multithreaded programs. - Samba, SSSD, and IdM include fixes for replica installation, ticket handling, logging, and authentication edge cases.
- Multipath, dm-crypt, and dm-verity fixes address I/O queuing, NVMe fabric events, and memory corruption risks.
- The
ldconfigutility no longer crashes after interrupted upgrades. - The
pcsutility fixes resource move, expired-constraint, and quorum-device validation behavior. - Podman and Container Tools receive fixes for secrets handling, rootless linger management, and database backend behavior.
- The web console adds script generation and improved storage management.
New Features
- Image Builder now supports partitioning modes and filesystem customization policies.
- Python 3.12, Ruby 3.3, PHP 8.2, nginx 1.24, MariaDB 10.11, and PostgreSQL 16 are available as new application streams.
- Identity Management now supports external IdP authentication using OAuth 2 Device Authorization Grant.
- Podman adds containers.conf modules, SQLite as the default backend for new installs, HereDoc support in Containerfiles, and progress reporting in the REST API.
- GCC Toolset 14, updated LLVM, Rust, Go, and GCC Toolset 13 components are included.
- SGX and Intel IDXD move to full support.
- New RHEL System Roles include bootloader, fapolicyd, snapshot management, and expanded networking, logging, and HA features.
- Multi-FD VM migration is now supported.
- The web console can generate Ansible and shell scripts and offers improved storage and virtualization workflows.
Known Issues
- IBM Z installation may assign unpredictable RoCE interface names when
net.naming-scheme=rhel-8.7is ignored for FID-enumerated cards. - RHEL installation fails on IBM Power 10 systems with LPAR and secure boot enabled.
- Anaconda running as an application can modify SELinux policy on the host system.
- RHEL for Edge image creation has limitations with custom mount points for rpm-ostree payloads.
- Some security profiles and tools have known limitations, including OpenSCAP memory usage, tailored profile handling, and certain SCAP rule incompatibilities.
- Several virtualization, networking, and storage scenarios have documented limitations, including VM snapshot support, NVMe/TCP multipath, and specific hardware/firmware combinations.
Hints
- RHEL 8.10 ships kernel
4.18.0-553. - For in-place upgrades from RHEL 7, supported paths include RHEL 7.9 to RHEL 8.8 or RHEL 8.10 on supported architectures.
- The
python3.12stack is installed withyum install python3.12andyum install python3.12-pip. - To install new module streams, use commands such as
yum module install ruby:3.3,yum module install php:8.2,yum module install nginx:1.24, andyum module install postgresql:16. - Podman SQLite is the default backend for new RHEL 8.10 installations; upgraded systems keep BoltDB unless changed explicitly.
- Several features are deprecated, including CNI networking,
pastaas a network name, BoltDB backend, SPICE, and various older container and language streams. - Some changes require follow-up actions, such as updating
sssd.conf, switching from SPICE to VNC for RHEL 9 migration, or usingauthselect/ansible-coreinstead of deprecated paths.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 8
Version: 4.18.0-553
Vendor release date: May 22, 2024
Original release notes: View on vendor site
Published on updatealert.io: Aug 8, 2026