Red Hat Enterprise Linux Server RHEL 9 Update Version RHEL 9.3 kernel 5.14.0-362.8.1
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.3 adds major installer, security, networking, storage, virtualization, and system role enhancements. It also includes key package rebases such as NetworkManager 1.44.0, OpenSSH hardening, GCC Toolset 13, and RHEL 9.3 kernel 5.14.0-362.8.1.
Update Details
Security
- Keylime rebased to 7.3.0, including fixes for CVE-2023-38200 and CVE-2023-38201.
- OpenSSH further reduces SHA-1 usage and prefers SHA-2 in more cryptographic scenarios.
- FIPS 140-3 EMS enforcement was expanded for TLS 1.2;
NO-ENFORCE-EMSis available for legacy compatibility, but it weakens FIPS compliance. - OpenSSL adds protections against Bleichenbacher-like RSA PKCS #1 v1.5 attacks.
- HTTP::Tiny now verifies TLS certificates by default, addressing CVE-2023-31486 and CVE-2023-31484.
- SELinux policy was tightened for Keylime ports and additional services, including FDO and systemd services.
- GnuTLS, NSS, and OpenSSL FIPS behavior was updated to require or optionally relax EMS handling for TLS 1.2.
- GnuPG, OpenSSL, and crypto-policies continue deprecating SHA-1 and other weak algorithms for cryptographic use.
Bug Fixes
- Installer fixes for Kickstart proxy handling, liveimg SSL verification, LUKS passphrase validation in FIPS mode, and driver update loading.
- NetworkManager and nmstate fixes for DNS handling, bonding options, interface naming, and restart behavior after D-Bus restarts.
- Storage and boot fixes including GRUB default kernel selection, NVMe/VMD detection, multipath persistent reservations, and kdump improvements.
- Identity Management fixes for PAC handling, SSSD behavior, Directory Server performance, and IdM/AD interoperability.
- Virtualization fixes for live migration, virtiofs attachment, Windows guest networking, and NVIDIA GPU passthrough stability.
- System role fixes for firewall, kdump, storage, podman, certificate, and rhc roles.
- Tooling fixes across dnf, rpm, sos, OpenSCAP, pcs, glibc, elfutils, and valgrind.
New Features
- AWS EC2 AMI images now support UEFI boot in addition to legacy BIOS boot.
- RHEL for Edge adds support for minimal-raw, edge-vsphere, and edge-ami image types, plus FDO container images.
- NetworkManager 1.44.0 adds new bond, bridge, VLAN, DNS, and link property support.
- Podman 4.6 introduces Quadlets, Podmansh, sigstore client support, zstd image transfer, and SQLite backend preview.
- RHEL system roles add systemd, keylime_server, postgresql, and expanded firewall, storage, podman, and kdump capabilities.
- RHEL 9.3 adds support for NVIDIA Grace CPUs, AutoIBRS, vTPM for containers, and ARM wifi/Bluetooth/camera support.
- New application streams include Node.js 20, Redis 7, .NET 8.0, GCC Toolset 13, LLVM Toolset 16.0.6, Rust Toolset 1.71.1, and Go Toolset 1.20.10.
Known Issues
- NVMe/FC devices can be unreliable in Kickstart installations and may require
inst.wait_for_disks=30. - OpenSSH 9.0-9.3 is incompatible with OpenSSL 3.2.2 unless OpenSSH is updated to 8.7p1-38.el9 or later.
- Some FIPS and PKINIT interoperability scenarios require
DEFAULT:SHA1orFIPS:NO-ENFORCE-EMSworkarounds. - Several virtualization scenarios remain limited, including some Windows guest behaviors, post-copy migration edge cases, and NVIDIA/Wayland limitations.
- Some installer, storage, and cloud-init scenarios still have documented workarounds or limitations.
Hints
- RHEL 9.3 supports in-place upgrade from RHEL 8.9 on supported architectures.
- The release uses kernel version 5.14.0-362.8.1.
- For FIPS compatibility with legacy TLS 1.2 systems,
update-crypto-policies --set FIPS:NO-ENFORCE-EMSis documented, but it violates FIPS 140-3 requirements. - NetworkManager now prefers keyfile format; ifcfg profiles are deprecated and migration is recommended.
- The
grub2-mkconfigdefault behavior changed with BLS: kernel command lines now come from BLS snippets unless overridden. - RHEL 9.3 deprecates several legacy technologies, including SHA-1 for cryptographic purposes, SCP, teamd/libteam, GTK 2, LibreOffice RPMs, and the
initial-setuppackage. - The
authandauthconfigKickstart commands require the AppStream repository because they depend onauthselect-compat.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: RHEL 9.3 kernel 5.14.0-362.8.1
Vendor release date: Nov 8, 2023
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026