Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.7 introduces post-quantum cryptography support, updated toolchains, Cockpit 344, and major installer, networking, virtualization, and container enhancements. It also documents notable fixes, known issues, and deprecations for RHEL 9.7.

Update Details

Security

  • System-wide crypto policies add the PQ subpolicy for post-quantum cryptography, including ML-KEM and ML-DSA support.
  • OpenSSL 3.5 adds support for ML-KEM, ML-DSA, and SLH-DSA, plus hybrid ML-KEM groups in the default TLS list.
  • NSS 3.112 adds ML-DSA and hybrid MLKEM1024 support; changing the NSS database password previously corrupted ML-DSA seeds.
  • Hybrid ML-KEM cryptography is supported in FIPS mode, and crypto-policies adds Ed25519 support in NSS.
  • SELinux policy updates add confinement for tuned-ppd, rules for qgs, and a type for /dev/diag.
  • Keylime 7.12.1 includes a security fix for CVE-2025-1057.
  • fs.protected_regular and fs.protected_fifos are enabled by default to reduce spoofing risk.
  • OpenSSL supports SSLKEYLOGFILE, but Red Hat warns it exposes TLS secrets and should only be used in test or debug environments.

Bug Fixes

  • Installer fixes include support for removing VDO volumes without the dm_vdo module, respecting BOOTIF, and checking disk space for bootc installs.
  • DNF and RPM fixes include correct URL reporting for dnf download --url, transient transaction tracking, and recording package digests during installation.
  • Networking fixes include preserving custom /etc/iproute2 settings, preventing kernel panics when SR-IOV VF counts are reduced, and improving xdp-loader features behavior.
  • Kernel and performance fixes include improved rtla timerlat, irqbalance crash fixes on aarch64, and better stalld scheduling behavior.
  • Storage fixes include multipath monitoring of offline paths, VDO crash fixes, and boot success for NVMe-FC mount points in /etc/fstab.
  • Virtualization fixes include improved VM migration, virtiofs stability, Windows guest fixes, and better device handling in libvirt/QEMU.
  • Identity Management fixes include corrected Directory Server behavior for referrals, monitoring, nested groups, and LMDB offline import.
  • System roles fixes include better RAID validation, LVM RAID support for encrypted/partitioned devices, and more reliable Podman, SELinux, and network role behavior.

New Features

  • RHEL Image Builder adds advanced partitioning, Kickstart injection for ISO builds, WSL2 images, and modularized content discovery in the GUI.
  • A new fips=1 boot menu entry is available for ISO installations.
  • Cockpit is rebased to version 344 with PatternFly 6 styling and improved storage, VM, networking, and branding support.
  • Valkey 8 is now available as a Redis-compatible key-value store.
  • Podman and Buildah gain new artifact management, Quadlet, and --link support for ADD and COPY.
  • RHEL 9.7 adds support for .NET 10.0, GCC Toolset 15, LLVM Toolset 20.1.8, Rust Toolset 1.88.0, and Go Toolset 1.24.
  • Virtualization adds features such as SCSI passthrough, SCSI3 persistent reservations, virtio-mem on IBM Z, and new ARM64 VM capabilities.
  • Identity Management adds IdM-to-IdM migration support and HSM support for CA/KRA keys.

Known Issues

  • NSS database password updates can corrupt ML-DSA seeds in affected systems; Red Hat references RHEL-114443.
  • NVMe/TCP kdump to an NVMe namespace can fail in some environments.
  • The auth and authconfig Kickstart commands require the AppStream repository.
  • bootc-image-builder does not support building images from private registries.
  • Device Mapper Multipath is not supported with NVMe/TCP; native NVMe multipathing must be used.
  • Some RHEL 9.7 virtualization scenarios remain unsupported or problematic, including several Windows guest and live migration edge cases.

Hints

  • Supported in-place upgrade paths from RHEL 8.10 include RHEL 9.4, 9.6, and 9.7 on supported architectures.
  • To enable FIPS during installation, use the fips=1 kernel boot option; fips-mode-setup is deprecated.
  • The bootc-image-builder tool now uses local container storage by default, so base images must be preloaded locally.
  • For PQC package verification, Red Hat provides pqrpm and the python3-dnf-plugin-multisig plugin; pqrpm is not a replacement for RPM.
  • The dnf4 command can be used interchangeably with dnf for DNF operations.
  • Several deprecated features are called out for future removal, including runc, ipset, libgcrypt, compat-openssl11, and fips-mode-setup.
  • The release notes state that RHEL 9.7 ships kernel version 5.14.0-611.5.1.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: RHEL 9.7 kernel 5.14.0-611.5.1

Vendor release date: Nov 12, 2025

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026