Views
16

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.4 adds major platform updates across security, virtualization, containers, networking, and developer tools. It also includes notable bug fixes, new system roles, and several deprecations; release date: 2024-04-30.

Update Details

Security

  • SELinux userspace rebased to 3.6 with deny rules and other policy enhancements.
  • OpenSSL adds a drop-in configuration directory for provider-specific settings and ships fips.so as a separate package.
  • OpenSSH limits artificial authentication delays to reduce user-enumeration risk.
  • crypto-policies adds finer SSH MAC control via the new etm@SSH tri-state option.
  • KDC adds extra checks for constrained delegation to address a forwardable-flag security issue.
  • GnuTLS 3.8.3 adds stricter TLS checks and new options, including disabling status_request on the client side.
  • stunnel 5.71 changes OpenSSL FIPS behavior and adds new TLS/OCSP-related features.
  • libkcapi 1.4.0 adds new hash and HMAC tools, including sm3sum and sm3hmac.
  • OpenSSL and crypto-policies deprecate SHA-1 for cryptographic purposes; SHA-1 can be re-enabled only for compatibility.
  • DEP/NX support is added to GRUB and shim to harden the pre-boot stage.

Bug Fixes

  • Installer now shows WWID identifiers for multipath storage devices and improves Kickstart time zone validation.
  • In-place upgrade handling was improved, including support for local DNF repositories, proxy use, and HTTPS repository fixes.
  • Multipath, dm-crypt, dm-verity, and NVMe-related storage issues were fixed, including device removal, queue handling, and boot problems.
  • glibc, ldconfig, make, and nscd received fixes for crashes, performance, and compatibility issues.
  • Directory Server, SSSD, and IdM fixes address login, caching, replication, and LDAP behavior problems.
  • Virtualization fixes include live migration, snapshot handling, device hotplug, and Windows guest stability improvements.
  • Rsyslog, firewalld, top, ReaR, and system roles received multiple usability and correctness fixes.

New Features

  • RHEL 9.4 introduces Python 3.12, Ruby 3.3, PHP 8.2, nginx 1.24, MariaDB 10.11, PostgreSQL 16, Git 2.43.0, and Git LFS 3.4.1.
  • Virtualization gains full support for KVM guests on 64-bit ARM, external snapshots as the default mechanism, and multi-FD migration.
  • Containers add Podman modules, SQLite as the default backend, HereDoc support in Containerfile, and multi-architecture farm builds as a Technology Preview.
  • RHEL for Edge adds FIPS-enabled image support and FDO SQL-backed Owner Voucher storage as a Technology Preview.
  • System roles expand significantly, including bootloader, fapolicyd, snapshot, and Microsoft SQL Server 2022 support.
  • Kernel and tooling updates include SGX support, IDXD support, eBPF rebasing, MGLRU enabled by default, and improved perf archive workflows.

Known Issues

  • Kickstart auth and authconfig require the AppStream repository.
  • reboot --kexec and inst.kexec do not provide a predictable system state.
  • RHEL for Edge installer images can fail to create some custom mount points for rpm-ostree payloads.
  • FIPS mode is not supported when building rpm-ostree images with RHEL image builder.
  • Device Mapper Multipath is not supported with NVMe/TCP; native NVMe multipathing should be used instead.
  • Several virtualization limitations remain, including some Windows guest issues, NBD-over-TLS migration problems, and NVIDIA/Wayland incompatibilities.
  • Some system roles and security profiles have limitations or workarounds, including firewall masking, SQL Server HA confinement, and STIG-related issues.

Hints

  • In-place upgrade from RHEL 8 to RHEL 9.4 is supported from RHEL 8.10 on the listed architectures; direct RHEL 7 to RHEL 9 upgrade is not supported.
  • MGLRU is enabled by default in RHEL 9.4 and may affect workloads tuned for very low vm.swappiness values.
  • The default Podman database backend for new RHEL 9.4 installations is SQLite; existing upgrades keep BoltDB unless changed explicitly.
  • /etc/system-fips is deprecated; use the fips=1 kernel parameter to enable FIPS mode.
  • CNI networking is deprecated in favor of Netavark, and pasta as a network name is deprecated.
  • Several Kickstart and installation workarounds are documented, including inst.wait_for_disks=30 for NVMe/FC and modprobe.blacklist= for driver updates.
  • ReaR now warns against setting TMPDIR in configuration files; export it in the shell environment instead.
  • The subscription-manager register --token method stops working at the end of November 2024.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.4

Vendor release date: Apr 30, 2024

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026