Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.6 introduces major updates across security, kernel, networking, virtualization, containers, and system roles. It also includes multiple rebases, new features, and notable bug fixes for RHEL 9.6.

Update Details

Security

  • GRUB2 is hardened with fixes for multiple vulnerabilities, including CVE-2024-45774, CVE-2024-45775, CVE-2024-45776, CVE-2024-45781, CVE-2024-45783, CVE-2025-0622, CVE-2025-0624, CVE-2025-0677, and CVE-2025-0690.
  • OpenSSL 3.2.2 adds certificate compression and Brainpool curves for TLS 1.3; crypto-policies can now block CBC ciphers and extend control to Java algorithm selection.
  • Landlock is introduced as a new Linux Security Module to restrict filesystem access for processes and improve container isolation.
  • SELinux policy updates confine additional services, add a boolean for QEMU Guest Agent confined commands, and assign a specific type to /dev/hfi1_0.
  • Keylime now requires HTTPS for revocation notifications and adds a new policy management tool.
  • FIPS-related updates include support for shlibsign in FIPS mode, stronger OpenSSL policy handling, and multiple crypto deprecations and restrictions.

Bug Fixes

  • DNF now reports reboot requirements more reliably and respects --norepopath in reposync.
  • NetworkManager and related networking components fix issues with route handling, DHCP hostname defaults, FEC configuration, VPN route mitigation for TunnelVision, and several driver behaviors.
  • Storage and filesystem fixes address multipath crashes, NVMe/TCP stability, installer boot-device detection, and kdump issues on encrypted or IBM Z systems.
  • Virtualization fixes include improved live migration behavior, better device handling, Windows guest boot and driver issues, and corrected reporting for high-memory VMs.
  • Directory Server, IdM, SSSD, and OpenLDAP receive multiple fixes for replication, TLS, backup, authentication, and query correctness.
  • System roles and support tools fix issues in sshd, firewall, storage, podman, certificate, and logging roles, plus sos obfuscation and cleanup improvements.

New Features

  • RHEL image builder and bootc-image-builder now support advanced partitioning for disk images.
  • The new sudo RHEL system role, aide role, keylime-policy tool, and snapm snapshot manager are introduced.
  • RHEL for Edge gains FDO-based deployment options and FIPS-compliant image capabilities.
  • DNF adds transient package transactions for image mode systems via dnf --transient.
  • NetworkManager and nmstate add support for IPvLAN, FEC encoding, routed DNS, and additional VPN and DHCP capabilities.
  • RHEL 9.6 adds newer application streams and toolchain versions, including Apache HTTP Server 2.4.62, Node.js 22, PHP 8.3, MySQL 8.4, GCC 11.5, LLVM 19.1.7, Rust 1.84.1, and Go 1.24.4.
  • Virtualization adds support for newer hardware platforms and features such as SEV-SNP, SCSI passthrough, S3-PR, and IBM z17 support.

Known Issues

  • Anaconda has several installation limitations, including Kickstart repository requirements, some USB and NVMe/FC boot scenarios, and issues with certain image-mode or encrypted-DNS workflows.
  • Containers may fail to start when fapolicyd is running unless specific rules are added.
  • OpenSSL and PKCS #11 token limitations can break TLS connections in some FIPS and RSA-PSS scenarios.
  • Several virtualization issues remain, including guest boot, migration, and device hot-plug limitations for specific hardware and guest combinations.
  • Some cloud and bootc deployment scenarios can fail when disk space is insufficient or when using certain image layouts.
  • SSSD and IdM have known limitations around large groups, PKINIT interoperability, and FIPS-related trust scenarios.

Hints

  • Supported in-place upgrade paths from RHEL 8.10 include upgrades to RHEL 9.4 and 9.6 on supported architectures.
  • For image mode systems, dnf --transient or persistence=transient can be used instead of bootc usr-overlay for temporary package changes.
  • Some deprecated features now require migration planning, including update-ca-trust usage, fips-mode-setup, ifcfg network profiles, runc, CNI, and several desktop applications and libraries.
  • RHEL 9.6 introduces new kernel parameters and deprecates others; administrators should review boot-time settings before upgrading.
  • The release notes explicitly state that some WSL images are self-supported only and have limitations such as no FIPS mode and no SELinux enforcing mode.
  • For FIPS and IdM interoperability, several crypto-policy subpolicies and EMS requirements may need to be considered during upgrades and cross-version integrations.

CVSS Scores

  • 7.6

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.6

Vendor release date: May 20, 2025

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026