Red Hat Enterprise Linux Server RHEL 9 Update Version RHEL 9.7 kernel 5.14.0-611.5.1
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.7 introduces post-quantum cryptography support, updated toolchains, Cockpit 344, and major installer, networking, virtualization, and container enhancements. It also documents notable fixes, known issues, and deprecations for RHEL 9.7.
Update Details
Security
- System-wide crypto policies add the
PQsubpolicy for post-quantum cryptography, including ML-KEM and ML-DSA support. - OpenSSL 3.5 adds support for ML-KEM, ML-DSA, and SLH-DSA, plus hybrid ML-KEM groups in the default TLS list.
- NSS 3.112 adds ML-DSA and hybrid MLKEM1024 support; changing the NSS database password previously corrupted ML-DSA seeds.
- Hybrid ML-KEM cryptography is supported in FIPS mode, and
crypto-policiesadds Ed25519 support in NSS. - SELinux policy updates add confinement for
tuned-ppd, rules forqgs, and a type for/dev/diag. - Keylime 7.12.1 includes a security fix for CVE-2025-1057.
fs.protected_regularandfs.protected_fifosare enabled by default to reduce spoofing risk.- OpenSSL supports
SSLKEYLOGFILE, but Red Hat warns it exposes TLS secrets and should only be used in test or debug environments.
Bug Fixes
- Installer fixes include support for removing VDO volumes without the
dm_vdomodule, respectingBOOTIF, and checking disk space for bootc installs. - DNF and RPM fixes include correct URL reporting for
dnf download --url, transient transaction tracking, and recording package digests during installation. - Networking fixes include preserving custom
/etc/iproute2settings, preventing kernel panics when SR-IOV VF counts are reduced, and improvingxdp-loader featuresbehavior. - Kernel and performance fixes include improved
rtla timerlat,irqbalancecrash fixes on aarch64, and betterstalldscheduling behavior. - Storage fixes include multipath monitoring of offline paths, VDO crash fixes, and boot success for NVMe-FC mount points in
/etc/fstab. - Virtualization fixes include improved VM migration, virtiofs stability, Windows guest fixes, and better device handling in libvirt/QEMU.
- Identity Management fixes include corrected Directory Server behavior for referrals, monitoring, nested groups, and LMDB offline import.
- System roles fixes include better RAID validation, LVM RAID support for encrypted/partitioned devices, and more reliable Podman, SELinux, and network role behavior.
New Features
- RHEL Image Builder adds advanced partitioning, Kickstart injection for ISO builds, WSL2 images, and modularized content discovery in the GUI.
- A new
fips=1boot menu entry is available for ISO installations. - Cockpit is rebased to version 344 with PatternFly 6 styling and improved storage, VM, networking, and branding support.
- Valkey 8 is now available as a Redis-compatible key-value store.
- Podman and Buildah gain new artifact management, Quadlet, and
--linksupport forADDandCOPY. - RHEL 9.7 adds support for .NET 10.0, GCC Toolset 15, LLVM Toolset 20.1.8, Rust Toolset 1.88.0, and Go Toolset 1.24.
- Virtualization adds features such as SCSI passthrough, SCSI3 persistent reservations, virtio-mem on IBM Z, and new ARM64 VM capabilities.
- Identity Management adds IdM-to-IdM migration support and HSM support for CA/KRA keys.
Known Issues
- NSS database password updates can corrupt ML-DSA seeds in affected systems; Red Hat references RHEL-114443.
- NVMe/TCP kdump to an NVMe namespace can fail in some environments.
- The
authandauthconfigKickstart commands require the AppStream repository. bootc-image-builderdoes not support building images from private registries.- Device Mapper Multipath is not supported with NVMe/TCP; native NVMe multipathing must be used.
- Some RHEL 9.7 virtualization scenarios remain unsupported or problematic, including several Windows guest and live migration edge cases.
Hints
- Supported in-place upgrade paths from RHEL 8.10 include RHEL 9.4, 9.6, and 9.7 on supported architectures.
- To enable FIPS during installation, use the
fips=1kernel boot option;fips-mode-setupis deprecated. - The
bootc-image-buildertool now uses local container storage by default, so base images must be preloaded locally. - For PQC package verification, Red Hat provides
pqrpmand thepython3-dnf-plugin-multisigplugin;pqrpmis not a replacement for RPM. - The
dnf4command can be used interchangeably withdnffor DNF operations. - Several deprecated features are called out for future removal, including
runc,ipset,libgcrypt,compat-openssl11, andfips-mode-setup. - The release notes state that RHEL 9.7 ships kernel version
5.14.0-611.5.1.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: RHEL 9.7 kernel 5.14.0-611.5.1
Vendor release date: Nov 12, 2025
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026