Views
12

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Red Hat Enterprise Linux 9.8 introduces major security, kernel, networking, storage, and tooling updates, including OpenSSH 9.9, GnuTLS 3.8.10, p11-kit 0.26.1, and new application streams such as PostgreSQL 18 and MariaDB 11.8. RHEL 9.8 was released as part of RHSA/RHEL 9.8 content on May 20, 2026. Reference IDs: RHSA-2026:3722, CVE-2025-11411, CVE-2026-33414.

Update Details

Security

  • OpenSSH 9.9 adds forwarding/key-use restrictions, ChannelTimeout, PerSourcePenalties, CanonicalMatchUser, and other hardening changes.
  • GnuTLS 3.8.10 adds post-quantum support for ML-KEM and ML-DSA, plus TLS certificate compression, RSA-OAEP, SHAKE, and improved OCSP handling.
  • crypto-policies adds support for hybrid ML-KEM and pure ML-DSA in GnuTLS and mlkem768x25519-sha256 for OpenSSH.
  • Valkey now runs with the redis_t SELinux type for consistent confinement.
  • AIDE 0.19.2 replaces libmhash with libnettle, updates defaults, and adds new logging and rule options.
  • fapolicyd 1.4.3 adds filter-rule support, database auto-sizing, and performance improvements.
  • p11-kit 0.26.1 updates PKCS #11 headers to 3.2 and improves trust-module behavior.
  • openwsman 2.8.1 improves TLS 1.3 support, OpenSSL 3.0 compatibility, and password handling.
  • openCryptoki 3.26.0 adds PQC support, including ML-DSA and ML-KEM.
  • CanonicalMatchUser in sshd_config prevents privilege escalation for capitalized Active Directory usernames.
  • Automated services no longer reset faillock counters, reducing password-guessing bypass risk.
  • Unbound 1.24.2 fixes CVE-2025-11411, a possible domain hijacking attack.
  • kpatch can now report which kernel CVEs are patched by live kernel updates.

Bug Fixes

  • Improved in-place upgrade reliability, including LVM/multipath, NVMe-FC, kernel-rt, and post-reboot DNF transaction handling.
  • Installer fixes include visible driver-disk input, text-mode language fallback, and better image-builder logging.
  • DNF fixes include protected-package removal handling, correct EVR comparison, and better advisory-filter transactions.
  • Multipath improvements include automatic removal of disconnected LUNs, better offline-path reporting, and faster uevent handling.
  • Directory Server fixes include replication, LMDB, access-log rotation, and NDN cache stability improvements.
  • Glibc fixes include NSS lookup stability, complete group merges, duplicate DNS query suppression, and safer origin-path handling.
  • Podman/Buildah fixes include database migration handling, Quadlet support, authfile handling, and boot-time restart policy enforcement.
  • Virtualization fixes include SEV-SNP boot issues, vTPM migration on shared storage, IBM Z post-copy networking, and live memory dump stability.
  • Storage and filesystem fixes include GFS2 write efficiency, multipath persistent reservations, and NVMe subsystem reset recovery.
  • Security-related fixes include AIDE file-change handling, clevis TPM2 JSON validation, ssh-agent smart-card access for confined users, and NSS ML-DSA seed preservation.

New Features

  • RHEL image builder can create disk images with advanced partitioning, Kickstart injection for ISO builds, and WSL2 images.
  • RHEL 9.8 adds PostgreSQL 18, MariaDB 11.8, Ruby 4.0, Python 3.14, OpenJDK 25, and GCC Toolset 15.
  • Systemd-cryptsetup can link LUKS2 volume keys to a kernel keyring.
  • io_uring is available for asynchronous I/O.
  • NetworkManager and Nmstate can configure IPv4 forwarding per interface.
  • HSR and PRP are fully supported, including RedBox and VLAN segmentation support.
  • The storage role can manage disk partitions, and the postgresql role supports PostgreSQL 18.
  • Cockpit 356 adds web console improvements such as timer editing, health warnings, and VM management enhancements.
  • RHEL Lightspeed adds color output for the command-line assistant and SAP documentation coverage.

Known Issues

  • kdump fails to start with UKI on confidential Azure VMs.
  • DNF may install a package from a local file even when that version is excluded by versionlock.
  • Firmware flash updates can fail on some Marvell QLogic Fibre Channel adapters.
  • IdM migration does not transfer SSH public keys.
  • Windows guest stop errors may occur on RHEL KVM hosts.
  • NetworkManager may allow system-wide profile creation by non-root users unless polkit rules are tightened.
  • kdump does not support NVMe/TCP connected namespaces.
  • FIPS bootc image creation fails on a FIPS-enabled host.
  • The command-line assistant may take 30-60 seconds to apply config changes and lacks reload support.

Hints

  • Supported in-place upgrade paths from RHEL 8.10 include RHEL 9.6 and RHEL 9.8 on supported architectures.
  • RHEL 7 cannot be upgraded directly to RHEL 9; upgrade to RHEL 8 first, then to RHEL 9.
  • For update-ca-trust, use update-ca-trust extract instead of running it without arguments.
  • The runc container runtime is deprecated; crun is the default runtime.
  • The ipset utility is deprecated; use nftables sets instead.
  • The qcow2-v2 image format is deprecated; use qcow2-v3.
  • The fips-mode-setup tool is deprecated; enable FIPS during installation or via image-builder/bootc workflows.
  • The podman BoltDB backend is deprecated; SQLite is the default.
  • Some features are Technology Preview only, including IdM Modern Web UI, TDX/SEV-SNP host support, and Podman Docker API compatibility.

Product Information

Vendor: Red Hat

Product: Enterprise Linux Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: RHEL 9

Version: 5.14.0-687.5.3

Vendor release date: May 20, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 11, 2026