Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.3 adds major installer, security, networking, storage, virtualization, and system role enhancements. It also includes key package rebases such as NetworkManager 1.44.0, OpenSSH hardening, GCC Toolset 13, and RHEL 9.3 kernel 5.14.0-362.8.1.

Update Details

Security

  • Keylime rebased to 7.3.0, including fixes for CVE-2023-38200 and CVE-2023-38201.
  • OpenSSH further reduces SHA-1 usage and prefers SHA-2 in more cryptographic scenarios.
  • FIPS 140-3 EMS enforcement was expanded for TLS 1.2; NO-ENFORCE-EMS is available for legacy compatibility, but it weakens FIPS compliance.
  • OpenSSL adds protections against Bleichenbacher-like RSA PKCS #1 v1.5 attacks.
  • HTTP::Tiny now verifies TLS certificates by default, addressing CVE-2023-31486 and CVE-2023-31484.
  • SELinux policy was tightened for Keylime ports and additional services, including FDO and systemd services.
  • GnuTLS, NSS, and OpenSSL FIPS behavior was updated to require or optionally relax EMS handling for TLS 1.2.
  • GnuPG, OpenSSL, and crypto-policies continue deprecating SHA-1 and other weak algorithms for cryptographic use.

Bug Fixes

  • Installer fixes for Kickstart proxy handling, liveimg SSL verification, LUKS passphrase validation in FIPS mode, and driver update loading.
  • NetworkManager and nmstate fixes for DNS handling, bonding options, interface naming, and restart behavior after D-Bus restarts.
  • Storage and boot fixes including GRUB default kernel selection, NVMe/VMD detection, multipath persistent reservations, and kdump improvements.
  • Identity Management fixes for PAC handling, SSSD behavior, Directory Server performance, and IdM/AD interoperability.
  • Virtualization fixes for live migration, virtiofs attachment, Windows guest networking, and NVIDIA GPU passthrough stability.
  • System role fixes for firewall, kdump, storage, podman, certificate, and rhc roles.
  • Tooling fixes across dnf, rpm, sos, OpenSCAP, pcs, glibc, elfutils, and valgrind.

New Features

  • AWS EC2 AMI images now support UEFI boot in addition to legacy BIOS boot.
  • RHEL for Edge adds support for minimal-raw, edge-vsphere, and edge-ami image types, plus FDO container images.
  • NetworkManager 1.44.0 adds new bond, bridge, VLAN, DNS, and link property support.
  • Podman 4.6 introduces Quadlets, Podmansh, sigstore client support, zstd image transfer, and SQLite backend preview.
  • RHEL system roles add systemd, keylime_server, postgresql, and expanded firewall, storage, podman, and kdump capabilities.
  • RHEL 9.3 adds support for NVIDIA Grace CPUs, AutoIBRS, vTPM for containers, and ARM wifi/Bluetooth/camera support.
  • New application streams include Node.js 20, Redis 7, .NET 8.0, GCC Toolset 13, LLVM Toolset 16.0.6, Rust Toolset 1.71.1, and Go Toolset 1.20.10.

Known Issues

  • NVMe/FC devices can be unreliable in Kickstart installations and may require inst.wait_for_disks=30.
  • OpenSSH 9.0-9.3 is incompatible with OpenSSL 3.2.2 unless OpenSSH is updated to 8.7p1-38.el9 or later.
  • Some FIPS and PKINIT interoperability scenarios require DEFAULT:SHA1 or FIPS:NO-ENFORCE-EMS workarounds.
  • Several virtualization scenarios remain limited, including some Windows guest behaviors, post-copy migration edge cases, and NVIDIA/Wayland limitations.
  • Some installer, storage, and cloud-init scenarios still have documented workarounds or limitations.

Hints

  • RHEL 9.3 supports in-place upgrade from RHEL 8.9 on supported architectures.
  • The release uses kernel version 5.14.0-362.8.1.
  • For FIPS compatibility with legacy TLS 1.2 systems, update-crypto-policies --set FIPS:NO-ENFORCE-EMS is documented, but it violates FIPS 140-3 requirements.
  • NetworkManager now prefers keyfile format; ifcfg profiles are deprecated and migration is recommended.
  • The grub2-mkconfig default behavior changed with BLS: kernel command lines now come from BLS snippets unless overridden.
  • RHEL 9.3 deprecates several legacy technologies, including SHA-1 for cryptographic purposes, SCP, teamd/libteam, GTK 2, LibreOffice RPMs, and the initial-setup package.
  • The auth and authconfig Kickstart commands require the AppStream repository because they depend on authselect-compat.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.3 kernel 5.14.0-362.8.1

Vendor release date: Nov 8, 2023

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026