Red Hat Enterprise Linux Server RHEL 9 Update Version RHEL 9.4
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.4 adds major platform updates across security, virtualization, containers, networking, and developer tools. It also includes notable bug fixes, new system roles, and several deprecations; release date: 2024-04-30.
Update Details
Security
- SELinux userspace rebased to 3.6 with deny rules and other policy enhancements.
- OpenSSL adds a drop-in configuration directory for provider-specific settings and ships
fips.soas a separate package. - OpenSSH limits artificial authentication delays to reduce user-enumeration risk.
- crypto-policies adds finer SSH MAC control via the new
etm@SSHtri-state option. - KDC adds extra checks for constrained delegation to address a forwardable-flag security issue.
- GnuTLS 3.8.3 adds stricter TLS checks and new options, including disabling
status_requeston the client side. - stunnel 5.71 changes OpenSSL FIPS behavior and adds new TLS/OCSP-related features.
- libkcapi 1.4.0 adds new hash and HMAC tools, including
sm3sumandsm3hmac. - OpenSSL and crypto-policies deprecate SHA-1 for cryptographic purposes; SHA-1 can be re-enabled only for compatibility.
- DEP/NX support is added to GRUB and shim to harden the pre-boot stage.
Bug Fixes
- Installer now shows WWID identifiers for multipath storage devices and improves Kickstart time zone validation.
- In-place upgrade handling was improved, including support for local DNF repositories, proxy use, and HTTPS repository fixes.
- Multipath, dm-crypt, dm-verity, and NVMe-related storage issues were fixed, including device removal, queue handling, and boot problems.
- glibc, ldconfig, make, and nscd received fixes for crashes, performance, and compatibility issues.
- Directory Server, SSSD, and IdM fixes address login, caching, replication, and LDAP behavior problems.
- Virtualization fixes include live migration, snapshot handling, device hotplug, and Windows guest stability improvements.
- Rsyslog, firewalld, top, ReaR, and system roles received multiple usability and correctness fixes.
New Features
- RHEL 9.4 introduces Python 3.12, Ruby 3.3, PHP 8.2, nginx 1.24, MariaDB 10.11, PostgreSQL 16, Git 2.43.0, and Git LFS 3.4.1.
- Virtualization gains full support for KVM guests on 64-bit ARM, external snapshots as the default mechanism, and multi-FD migration.
- Containers add Podman modules, SQLite as the default backend, HereDoc support in Containerfile, and multi-architecture farm builds as a Technology Preview.
- RHEL for Edge adds FIPS-enabled image support and FDO SQL-backed Owner Voucher storage as a Technology Preview.
- System roles expand significantly, including bootloader, fapolicyd, snapshot, and Microsoft SQL Server 2022 support.
- Kernel and tooling updates include SGX support, IDXD support, eBPF rebasing, MGLRU enabled by default, and improved perf archive workflows.
Known Issues
- Kickstart
authandauthconfigrequire the AppStream repository. reboot --kexecandinst.kexecdo not provide a predictable system state.- RHEL for Edge installer images can fail to create some custom mount points for rpm-ostree payloads.
- FIPS mode is not supported when building rpm-ostree images with RHEL image builder.
- Device Mapper Multipath is not supported with NVMe/TCP; native NVMe multipathing should be used instead.
- Several virtualization limitations remain, including some Windows guest issues, NBD-over-TLS migration problems, and NVIDIA/Wayland incompatibilities.
- Some system roles and security profiles have limitations or workarounds, including firewall masking, SQL Server HA confinement, and STIG-related issues.
Hints
- In-place upgrade from RHEL 8 to RHEL 9.4 is supported from RHEL 8.10 on the listed architectures; direct RHEL 7 to RHEL 9 upgrade is not supported.
- MGLRU is enabled by default in RHEL 9.4 and may affect workloads tuned for very low
vm.swappinessvalues. - The default Podman database backend for new RHEL 9.4 installations is SQLite; existing upgrades keep BoltDB unless changed explicitly.
/etc/system-fipsis deprecated; use thefips=1kernel parameter to enable FIPS mode.- CNI networking is deprecated in favor of Netavark, and
pastaas a network name is deprecated. - Several Kickstart and installation workarounds are documented, including
inst.wait_for_disks=30for NVMe/FC andmodprobe.blacklist=for driver updates. - ReaR now warns against setting
TMPDIRin configuration files; export it in the shell environment instead. - The
subscription-manager register --tokenmethod stops working at the end of November 2024.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: RHEL 9.4
Vendor release date: Apr 30, 2024
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026