Red Hat Enterprise Linux Server RHEL 9 Update Version RHEL 9.2 kernel 5.14.0-284.11.1
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.2 adds major installer, security, networking, container, and identity management updates. It also includes many package rebases, new system roles, and fixes for installation, storage, virtualization, and kernel behavior.
Update Details
Security
- OpenSSL rebased to 3.0.7; default provider now includes RIPEMD160.
- SELinux user-space packages updated to 3.5, with stricter policy validation and reduced memory usage in libselinux.
- Keylime rebased to 6.5.2 and addresses CVE-2022-3500.
- OpenSCAP rebased to 1.3.7 with fixes for OVAL processing and XML output handling.
- SCAP Security Guide rebased to 0.1.66 and adds a new idle session termination rule.
- Clevis now accepts external tokens for automated encryption workflows.
- Rsyslog TLS-encrypted logging now supports multiple CA files and reduced privileges.
- fapolicyd now filters RPM database files through
/etc/fapolicyd/rpm-filter.conf. - Libreswan rebased to 4.9 with IKEv2 and authentication enhancements.
- libssh rebased to 0.10.4 and adds smart card support; SCP API is deprecated.
- NSS raises the minimum RSA key size to 1023 bits.
- FIPS-enabled systems now require TLS Extended Master Secret for TLS 1.2 connections.
- Node.js 18.14 / npm 9 removes unscoped authentication settings for security reasons.
- MIT Kerberos and IdM now enforce MS-PAC structure in Kerberos tickets.
- IdM now supports FIPS 140-3-compliant key encryption templates for new realms.
Bug Fixes
- Installer fixes for custom partitioning, GPT layout creation, kickstart repo options, and LUKS passphrase validation.
- ReaR fixes for IBM Z recovery, including excluded DASDs and non-LVM XFS restore handling.
- DNF fixes for rollback of package groups/environments and security upgrades involving architecture changes.
- NetworkManager fixes for DHCP lease preservation during reapply and improved VLAN, ECMP, loopback, and MPTCP handling.
- Systemd and systemd-udevd updates improve device timeout handling, shutdown logging, and InfiniBand naming consistency.
- Kernel and kdump fixes for FADump, NVMe/FC, LUKS-encrypted targets, 64K ARM page size, and crashkernel handling.
- Pacemaker and pcs fixes for cluster property handling, resource validation, and clean shutdown behavior.
- Samba, SSSD, Directory Server, and IdM fixes for authentication, replication, certificate handling, and user lookup behavior.
- Podman, container-tools, and toolbox updates add Quadlet, sigstore support, auditing events, and RHEL 9 container support.
- OpenJDK fixes for FIPS mode, RSA-PSS validation, XML signatures, and PKCS#11 token handling.
New Features
- Image Builder web console improvements for blueprint import/export, customization, and image management.
- Support for creating custom files and directories under
/etcin image blueprints. - RHEL for Edge enhancements including Ignition support and optional FDO customization.
- New
dnf offline-upgradecommand for offline updates. - Python 3.11, nginx 1.22, PostgreSQL 15, Git 2.39.1, and Git LFS 3.2.0 are now available.
- Systemd rebased to 252 with new timeout, logging, and transient unit features.
- NetworkManager adds ECMP weight support, loopback management, VLAN protocol selection, and MPTCP support.
- New
kernel-64kpackage for 64-bit ARM systems. - New
passt,synce4l,tomcat,jmc, andrhcsystem role support are introduced. - Podman gains auditing events, sigstore support, Quadlet Technology Preview, and custom DNS selection.
- New RHEL system roles for Active Directory integration, journald, and remote host configuration.
- New SCAP rule for idle session termination and new CIS RHEL 9 profiles.
Known Issues
- RHEL 9.2 installer may fail in several kickstart, iSCSI, USB, proxy, and storage scenarios.
- RHEL 9.2 known issues include kdump failures on some 64K ARM and IBM Z configurations.
- Some IdM and Kerberos scenarios fail in FIPS mode or with mixed-version trust relationships.
- OpenSSL PKCS#11 token handling can fail for raw RSA or RSA-PSS signatures in some TLS scenarios.
- Certain virtualization workflows remain limited, including some VM migration, NVIDIA passthrough, and snapshot cases.
- Some desktop and web console issues remain, including VNC resolution problems and Firefox add-on loss after upgrade.
- NetworkManager, nm-cloud-setup, and team configuration can still cause edge-case networking issues.
- OpenSCAP and Ansible remediation may require extra collections or manual workarounds in some cases.
- The
systemd-resolvedservice, WireGuard, and KTLS are Technology Preview only. - The CNI network stack is deprecated; Netavark is the recommended container network stack.
Hints
- RHEL 8.8 to RHEL 9.2 in-place upgrade is supported on selected architectures; RHEL 7 must upgrade through RHEL 8 first.
- The
leapp-upgrade-el8toel9package now includes required data files; manual downloads are no longer needed. - RPM signatures are checked automatically during in-place upgrade unless
--nogpgcheckis used. - Systems subscribed to RHSM are automatically registered with Red Hat Insights during upgrade unless disabled.
- On 64-bit ARM, choose page size at installation time;
kernel-64kmust be installed via Kickstart. - The
CNInetwork stack is deprecated; useNetavarkfor new container deployments. - Several deprecated Kickstart commands include
timezone --ntpservers,timezone --nontp,logging --level, and%anaconda. - SHA-1 is deprecated for cryptographic purposes;
DEFAULT:SHA1orLEGACYmay be needed for compatibility cases. - The
--tokenoption insubscription-manager registeris deprecated. - RHEL 9.2 ships kernel
5.14.0-284.11.1.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: RHEL 9.2 kernel 5.14.0-284.11.1
Vendor release date: May 10, 2023
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026