- Issued:
- 2025-11-11
- Updated:
- 2025-11-11
RHBA-2025:20566 - Bug Fix Advisory
Synopsis
crypto-policies bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for crypto-policies is now available for Red Hat Enterprise Linux 9.
Description
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9 Release Notes linked from the References section.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for ARM 64 9 aarch64
Fixes
- RHEL-91839 - add a PQ subpolicy to RHEL-9 crypto-policies
- RHEL-103793 - X25519-MLKEM768 should be aliased to MLKEM768-X25519 [rhel-9]
- RHEL-104607 - enable ED25519 in RHEL-9 NSS policy
- RHEL-103786 - Update crypto policies to support PQC in rpm-sequoia [rhel-9]
- RHEL-103963 - enable ML-DSA in NSS in PQ subpolicy [rhel-9]
- RHEL-106866 - Enable ML-KEM hybrids in NSS in PQ subpolicy [rhel-9]
- RHEL-111491 - Red Hat packages cannot be installed with dnf multisig plugin
- RHEL-112697 - allow PQ algorithms in all rpm-sequoia crypto-policies (RHEL-9)
CVEs
(none)
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
| SRPM | |
|---|---|
| crypto-policies-20250905-1.git377cc42.el9_7.src.rpm | SHA-256: a8ccbe1e1a1b7263941b20d156594925a70017d6de72889dfa7618d8b02a33aa |
| x86_64 | |
| crypto-policies-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 38078d704d7be136211a17da34692e9e669fd59a43ec2e82b22082e280c6f290 |
| crypto-policies-scripts-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 5e0cbb9b384a94aebde15ab9a1c01b4dd33c52734e1bb559b43fb18b075295ab |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM | |
|---|---|
| crypto-policies-20250905-1.git377cc42.el9_7.src.rpm | SHA-256: a8ccbe1e1a1b7263941b20d156594925a70017d6de72889dfa7618d8b02a33aa |
| s390x | |
| crypto-policies-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 38078d704d7be136211a17da34692e9e669fd59a43ec2e82b22082e280c6f290 |
| crypto-policies-scripts-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 5e0cbb9b384a94aebde15ab9a1c01b4dd33c52734e1bb559b43fb18b075295ab |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM | |
|---|---|
| crypto-policies-20250905-1.git377cc42.el9_7.src.rpm | SHA-256: a8ccbe1e1a1b7263941b20d156594925a70017d6de72889dfa7618d8b02a33aa |
| ppc64le | |
| crypto-policies-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 38078d704d7be136211a17da34692e9e669fd59a43ec2e82b22082e280c6f290 |
| crypto-policies-scripts-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 5e0cbb9b384a94aebde15ab9a1c01b4dd33c52734e1bb559b43fb18b075295ab |
Red Hat Enterprise Linux for ARM 64 9
| SRPM | |
|---|---|
| crypto-policies-20250905-1.git377cc42.el9_7.src.rpm | SHA-256: a8ccbe1e1a1b7263941b20d156594925a70017d6de72889dfa7618d8b02a33aa |
| aarch64 | |
| crypto-policies-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 38078d704d7be136211a17da34692e9e669fd59a43ec2e82b22082e280c6f290 |
| crypto-policies-scripts-20250905-1.git377cc42.el9_7.noarch.rpm | SHA-256: 5e0cbb9b384a94aebde15ab9a1c01b4dd33c52734e1bb559b43fb18b075295ab |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.