Red Hat Enterprise Linux Server RHEL 9 Update Version 5.14.0-503.11.1
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.5 introduces major security, networking, container, and tooling updates, including OpenSSL 3.2.2, NSS 3.101, and new system roles. It also adds notable fixes for installation, storage, virtualization, and identity management. Reference IDs: RHEL 9.5, RHEA-2024:11235, RHSA-2025:0377, RHSA-2025:3773.
Update Details
Security
- OpenSSL rebased to 3.2.2, adding certificate compression, Brainpool curves for TLS 1.3, and fixes for CSR handling and EC signature timing issues.
- NSS rebased to 3.101 with DTLS 1.3, PBMAC1 for PKCS#12, experimental post-quantum key agreement support, and enforcement that RSA certificates with keys shorter than 2048 bits stop working.
- crypto-policies now extend algorithm selection control to Java, including protocol, cipher, and signature policy alignment.
- fips-mode-setup now blocks enabling FIPS mode when open LUKS volumes use Argon2 KDF, helping prevent non-FIPS configurations.
- SELinux policy adds a boolean to allow QEMU Guest Agent to run confined commands, and confines nbdkit and bootupd to reduce privilege escalation risk.
- clevis 20 includes security fixes for static-analysis-reported issues and improves password generation entropy.
- libreswan 4.15 improves IPsec handling, including IPv6 SAN certificate support and tighter IKEv1 proposal handling.
- NetworkManager can mitigate CVE-2024-3661 (TunnelVision) in VPN profiles when using the supported routing-table approach.
- GnuPG, OpenSSH, and OpenSSL-related changes tighten cryptographic behavior and deprecate weaker or unsafe algorithms and modes.
Bug Fixes
- Kickstart and installer fixes for dhcpclass handling, virtual network device stability, stale network link files, and several installation failures.
- DNF fixes for autoremove behavior, duplicate removal exit codes, reinstall repository cost handling, and history rollback edge cases.
- Network fixes for IPv6 privacy handling, large routing tables, IPsec VPN options, and Netavark DNS TCP query resolution.
- Storage and multipath fixes for NVMe, flush-on-last-delete behavior, booting from NVMe-FC, and multipath device mapping.
- Virtualization fixes for live migration, post-copy recovery, virtiofs attachment, Windows guest issues, and VM boot reliability.
- Identity Management fixes for replication, certificate renewal, directory server searches, and SSSD integration issues.
- System roles fixes for podman, storage, logging, sshd, bootloader, network, and firewall automation behavior.
- Kernel and tooling fixes for eBPF, kdump, GDB, glibc, valgrind, SystemTap, and performance tools.
New Features
- New sudo RHEL system role for centralized sudo configuration management.
- OpenTelemetry Collector support for RHEL cloud instances, including AWS telemetry export.
- cockpit-files adds a file browser to the RHEL web console.
- BIND 9.18 support with DoT, DoH, and TLS zone transfers.
- Node.js 22 module stream is fully supported, and GCC Toolset 14 is introduced.
- GCC, GDB, Valgrind, SystemTap, elfutils, libabigail, PCP, and Grafana are updated to newer upstream versions.
- New support for GFS2 configuration via the gfs2 system role and expanded storage, logging, podman, and ssh system role capabilities.
- Image mode for RHEL gains FIPS support, logically bound app images, and additional bootc-image-builder capabilities.
- New kernel and platform features include eBPF rebasing, tmpfs quotas, DAX support for Ext4/XFS, EROFS support, and additional hardware enablement.
Known Issues
- Several installer and image creation scenarios still have limitations, including some Kickstart command dependencies, USB media detection issues, and bootc-image-builder restrictions with private registries.
- OpenSSL PKCS #11 token handling can fail for RSA/RSA-PSS signatures in some TLS 1.3 scenarios.
- Some networking and VPN scenarios remain limited, including kTLS TLS 1.3 offload support and certain interface renaming or boot-time discovery cases.
- Multiple virtualization issues remain for specific guest OSes, GPU passthrough, live migration, and Windows guest behaviors.
- Some cloud and container workflows have limitations, including bootc registry login differences and root filesystem expansion behavior without cloud-init.
- RHEL 9.5 notes list several unresolved issues for SSSD, IdM, desktop components, and supportability tools.
Hints
- Supported in-place upgrade from RHEL 8.10 to RHEL 9.5 is available on x86-64, POWER9 little-endian and later, and IBM Z excluding z13.
- OpenJDK 17 becomes the default Java implementation in RHEL 9; java-11-openjdk receives no further updates in the base stream.
- Podman v5.0 changes defaults and behavior: SQLite becomes the default backend, rootless networking defaults to pasta, and containers.conf system connection data becomes read-only.
- FIPS mode should be enabled at install time or via image-building workflows; fips-mode-setup is deprecated.
- Several deprecated technologies are called out for migration planning, including ifcfg network profiles, teamd, libdb, OpenSSL engines, and various desktop applications.
- The release notes explicitly state that RHEL 9.5 is distributed with kernel version 5.14.0-503.11.1.
- For some system roles and container workflows, credentials and secrets should be protected with Ansible Vault.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: 5.14.0-503.11.1
Vendor release date: Nov 12, 2024
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026