Red Hat Enterprise Linux Server RHEL 9 Update Version RHEL 9.0 kernel 5.14.0-70
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.0 introduces major security hardening, updated core components such as OpenSSL 3.0.1 and OpenSSH 8.7p1, and broad platform changes across networking, storage, virtualization, and desktop. It also documents notable bug fixes, deprecations, technology previews, and known issues for RHEL 9.0.
Update Details
Security
- SHA-1 is deprecated for cryptographic use; RHEL 9 disables SHA-1 signatures by default in most crypto policies, with limited exceptions such as HMAC and interoperability cases.
- System-wide crypto policies were tightened by disabling older protocols and algorithms including TLS 1.0/1.1, DTLS 1.0, RC4, Camellia, DSA, 3DES, and FFDHE-1024.
- OpenSSL 3.0.1 adds provider-based crypto, FIPS-aware behavior, and support for newer algorithms and protocols.
- OpenSSH 8.7p1 adds SFTP-by-default for file transfer, FIDO/U2F support, private key protection in RAM, and a minimal RSA key size option.
- SELinux policy and defaults were hardened, including improved policy coverage, removal of
SELINUX=disabledkernel support via config file alone, andselinuxuser_execmoddisabled by default. - NSS removes legacy DBM support and raises the minimum RSA key size to 1023 bits.
- OpenSCAP and SCAP Security Guide were updated, including new profiles and compressed CVE OVAL feeds for compliance scanning.
- FIPS-related behavior changed across components, including OpenSSL provider handling, openCryptoki token migration requirements, and crypto-policy interactions.
Bug Fixes
- Anaconda and installer behavior were improved, including automatic network activation, static hostname handling, and fixes for boot order and kickstart workflows.
- DNF/RPM and package management received updates such as zstd compression, sqlite-based RPM database, weak dependency controls, and modular metadata preservation in createrepo_c.
- Networking fixes include improved firewalld zone behavior, NetworkManager enhancements, and corrected handling of hostnames and interface naming.
- Kernel and kdump fixes address crashkernel handling, vmcore capture, module loading, and several architecture-specific issues.
- Storage and filesystem fixes include multipath improvements, GFS2 format changes, NVMe/TCP support, and LVM device selection behavior.
- Identity Management and SSSD fixes improve Kerberos, keytab discovery, sudo behavior, and Directory Server authentication handling.
- Virtualization fixes include QEMU/libvirt updates, virtiofs support, VM snapshot limitations, and guest/device handling improvements.
- Desktop and web console fixes include GNOME 40 updates, PipeWire audio handling, and Cockpit usability improvements.
New Features
- GNOME 40 is the default desktop environment, with PipeWire as the default audio service.
- NetworkManager now stores new connection profiles in keyfile format by default.
- cgroup v2 is enabled by default in RHEL 9.
- The GRUB configuration layout is unified across CPU architectures.
- RHEL for Edge gains Greenboot health checks, rpm-ostree enhancements, and improved image-building capabilities.
- Image Builder adds filesystem customization and bootable installer image creation.
- New or updated application streams include Python 3.9, Node.js 16, Ruby 3.0, PHP 8.0, Git 2.31, PostgreSQL 13, MySQL 8.0, MariaDB 10.5, Redis 6.2, and .NET 6.0.
- Virtualization adds vTPM support, virtiofs, modular libvirt daemons, and QEMU built with Clang.
- RHEL system roles expand significantly, including firewall, VPN, HA cluster, metrics, and Microsoft SQL Server management roles.
Known Issues
- Kexec-based installation or reboot does not provide a predictable system state.
- Some USB-created installation media may not be detected as local media during installation.
- Kdump may fail without explicit crashkernel reservation or on encrypted targets with insufficient memory.
- OpenSSL FIPS and PKCS#11 interactions can fail in some TLS scenarios.
- RHEL 9.0 has several virtualization limitations, including some VM snapshot, NVIDIA/Wayland, and failover NIC issues.
- Some Identity Management PKINIT scenarios require enabling
DEFAULT:SHA1for compatibility with older or non-RHEL KDCs. - Device Mapper Multipath is not supported with NVMe/TCP.
- Several installer, networking, and desktop issues are documented as known issues for RHEL 9.0.
Hints
- In-place upgrade is supported from RHEL 8.6 to RHEL 9.0 on selected architectures; direct in-place upgrade from RHEL 7 to RHEL 9 is not supported.
- To re-enable SHA-1 for compatibility, use
update-crypto-policies --set DEFAULT:SHA1or theLEGACYpolicy, but this reduces security. - To disable SELinux, add
selinux=0to the kernel command line; changing/etc/selinux/configalone is no longer sufficient. - NetworkManager now prefers keyfile profiles;
ifcfgformat remains supported but is deprecated. - OpenSSH uses SFTP by default for SCP-style transfers; use
-Oto force the legacy SCP/RCP protocol if needed. - OpenSSL provider selection can affect remote access; enabling a non-default provider may break services such as OpenSSH.
- For FIPS compliance with openCryptoki, migrate tokens to the new data format before enabling FIPS mode.
- RHEL 9 installation media is ISO-based; the installation ISO is large and USB media is recommended.
- The
crashkernel=autoboot option is no longer supported in RHEL 9.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: RHEL 9.0 kernel 5.14.0-70
Vendor release date: May 18, 2022
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026