Red Hat Enterprise Linux Server RHEL 9 Update Version 5.14.0-687.5.3
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Red Hat Enterprise Linux 9.8 introduces major security, kernel, networking, storage, and tooling updates, including OpenSSH 9.9, GnuTLS 3.8.10, p11-kit 0.26.1, and new application streams such as PostgreSQL 18 and MariaDB 11.8. RHEL 9.8 was released as part of RHSA/RHEL 9.8 content on May 20, 2026. Reference IDs: RHSA-2026:3722, CVE-2025-11411, CVE-2026-33414.
Update Details
Security
- OpenSSH 9.9 adds forwarding/key-use restrictions,
ChannelTimeout,PerSourcePenalties,CanonicalMatchUser, and other hardening changes. - GnuTLS 3.8.10 adds post-quantum support for ML-KEM and ML-DSA, plus TLS certificate compression, RSA-OAEP, SHAKE, and improved OCSP handling.
- crypto-policies adds support for hybrid ML-KEM and pure ML-DSA in GnuTLS and
mlkem768x25519-sha256for OpenSSH. - Valkey now runs with the
redis_tSELinux type for consistent confinement. - AIDE 0.19.2 replaces
libmhashwithlibnettle, updates defaults, and adds new logging and rule options. - fapolicyd 1.4.3 adds filter-rule support, database auto-sizing, and performance improvements.
- p11-kit 0.26.1 updates PKCS #11 headers to 3.2 and improves trust-module behavior.
- openwsman 2.8.1 improves TLS 1.3 support, OpenSSL 3.0 compatibility, and password handling.
- openCryptoki 3.26.0 adds PQC support, including ML-DSA and ML-KEM.
- CanonicalMatchUser in
sshd_configprevents privilege escalation for capitalized Active Directory usernames. - Automated services no longer reset faillock counters, reducing password-guessing bypass risk.
- Unbound 1.24.2 fixes CVE-2025-11411, a possible domain hijacking attack.
- kpatch can now report which kernel CVEs are patched by live kernel updates.
Bug Fixes
- Improved in-place upgrade reliability, including LVM/multipath, NVMe-FC, kernel-rt, and post-reboot DNF transaction handling.
- Installer fixes include visible driver-disk input, text-mode language fallback, and better image-builder logging.
- DNF fixes include protected-package removal handling, correct EVR comparison, and better advisory-filter transactions.
- Multipath improvements include automatic removal of disconnected LUNs, better offline-path reporting, and faster uevent handling.
- Directory Server fixes include replication, LMDB, access-log rotation, and NDN cache stability improvements.
- Glibc fixes include NSS lookup stability, complete group merges, duplicate DNS query suppression, and safer origin-path handling.
- Podman/Buildah fixes include database migration handling, Quadlet support, authfile handling, and boot-time restart policy enforcement.
- Virtualization fixes include SEV-SNP boot issues, vTPM migration on shared storage, IBM Z post-copy networking, and live memory dump stability.
- Storage and filesystem fixes include GFS2 write efficiency, multipath persistent reservations, and NVMe subsystem reset recovery.
- Security-related fixes include AIDE file-change handling, clevis TPM2 JSON validation, ssh-agent smart-card access for confined users, and NSS ML-DSA seed preservation.
New Features
- RHEL image builder can create disk images with advanced partitioning, Kickstart injection for ISO builds, and WSL2 images.
- RHEL 9.8 adds PostgreSQL 18, MariaDB 11.8, Ruby 4.0, Python 3.14, OpenJDK 25, and GCC Toolset 15.
- Systemd-cryptsetup can link LUKS2 volume keys to a kernel keyring.
- io_uring is available for asynchronous I/O.
- NetworkManager and Nmstate can configure IPv4 forwarding per interface.
- HSR and PRP are fully supported, including RedBox and VLAN segmentation support.
- The storage role can manage disk partitions, and the postgresql role supports PostgreSQL 18.
- Cockpit 356 adds web console improvements such as timer editing, health warnings, and VM management enhancements.
- RHEL Lightspeed adds color output for the command-line assistant and SAP documentation coverage.
Known Issues
- kdump fails to start with UKI on confidential Azure VMs.
- DNF may install a package from a local file even when that version is excluded by versionlock.
- Firmware flash updates can fail on some Marvell QLogic Fibre Channel adapters.
- IdM migration does not transfer SSH public keys.
- Windows guest stop errors may occur on RHEL KVM hosts.
- NetworkManager may allow system-wide profile creation by non-root users unless polkit rules are tightened.
- kdump does not support NVMe/TCP connected namespaces.
- FIPS bootc image creation fails on a FIPS-enabled host.
- The command-line assistant may take 30-60 seconds to apply config changes and lacks reload support.
Hints
- Supported in-place upgrade paths from RHEL 8.10 include RHEL 9.6 and RHEL 9.8 on supported architectures.
- RHEL 7 cannot be upgraded directly to RHEL 9; upgrade to RHEL 8 first, then to RHEL 9.
- For
update-ca-trust, useupdate-ca-trust extractinstead of running it without arguments. - The
runccontainer runtime is deprecated;crunis the default runtime. - The
ipsetutility is deprecated; use nftables sets instead. - The
qcow2-v2image format is deprecated; useqcow2-v3. - The
fips-mode-setuptool is deprecated; enable FIPS during installation or via image-builder/bootc workflows. - The
podmanBoltDB backend is deprecated; SQLite is the default. - Some features are Technology Preview only, including IdM Modern Web UI, TDX/SEV-SNP host support, and Podman Docker API compatibility.
Product Information
Vendor: Red Hat
Product: Enterprise Linux Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: RHEL 9
Version: 5.14.0-687.5.3
Vendor release date: May 20, 2026
Original release notes: View on vendor site
Published on updatealert.io: Aug 11, 2026