[ANNOUNCE] SUSE Linux Enterprise Server 16.1 RC3 is out!
SUSE Beta Program
beta-programs at suse.com
Fri Sep 11 08:23:24 UTC 2026
SUSE Linux Enterprise Server 16.1 - the RC3 Milestone has been
achieved!
SUSE Linux Enterprise Server (SLES) 16.1 Release Candidate 3 (RC3) is
now available. This is an intermediate milestone on the road to
General Availability.
Release Highlights (changes since RC2)
Covers SLES, SLES for SAP, and SLE High Availability across all four
architectures: x86‑64, Arm64 (aarch64), IBM Power (ppc64le), and
IBM Z (s390x). As a Release Candidate, this build is intended for
validation and feedback, not production.
RC3 is a broad maintenance and hardening refresh rather than a feature
defining milestone. The full distribution was rebuilt for the RC3
code stream, with roughly 160+ source packages carrying real content
changes on top of the rebuild. On a base SLES install that nets out to
about 23 packages added, 34 removed, and several hundred genuinely
upgraded (the remainder are rebuilds). The emphasis this cycle is
clear: a large security roll-up, a step forward in SELinux and
system-integrity tooling, refreshed developer toolchains, and a
modernized VPN/networking and virtualization stack. The kernel
stays on 6.12.0 although traded stability kABI in the RC3 kernel in
favor of adding Post Quantum Cryptography feature. Dropped kernel
modules:
- The preparatory sha3 patches remove the individual arch-optimized
kernel modules: sha3-ce.ko (arm64), sha3_256_s390.ko (s390x),
sha3_512_s390.ko (s390x).
- The arch-optimized code now lives in the new common sha3 code.
- The sha3-generic module is gone.
A few things worth knowing about
1. Sizeable security roll-up. RC3 folds in a wide set of CVE fixes.
Highlights include RabbitMQ (ten CVEs — management-UI XSS and
OAuth/authorization issues, addressed via the move to 4.1), 7‑Zip
(heap-overflow RCE, CVE‑2026‑14266), and kronosnet in the HA stack
(three CVEs). Alongside these, security-relevant components were
refreshed: Firefox 140.13 ESR, Samba 4.23.10, Wireshark 4.6.8, BIND
9.20.26, Unbound 1.25.2, dnsdist, libssh, and OpenJDK 17/21/25 .
2. SELinux moves up a version — and becomes harder to skip. The full
SELinux userspace goes 3.10 → 3.11 (libselinux, libsepol,
libsemanage, policycoreutils, checkpolicy, mcstrans, setools)
with a refreshed selinux-policy. Notably, RPM now automatically
pulls in rpm-plugin-selinux whenever a SELinux policy is installed ,
and new himmelblau-selinux / drbd-selinux policy modules ship.
Teams running enforcing mode should re-run policy validation
against this build.
3. RPM integrity/audit plugins are now modular. The RPM plugins have
been split into individually installable packages —
rpm-plugin-ima, rpm-plugin-imaevmsign, rpm-plugin-fapolicyd,
rpm-plugin-selinux, rpm-plugin-prioreset, rpm-plugin-syslog .
This makes IMA/EVM measured boot, fapolicyd application
allow-listing, and audit integration opt-in and easier to compose
for hardened deployments.
4. Post-quantum cryptography advances. liboqs 0.15 → 0.16 and the
OpenSSL oqs-provider 0.9 → 0.11, keeping the PQC stack current for
early adopters testing quantum-resistant TLS/KEM algorithms.
5. Developer toolchains refreshed — mind the Go rotation. GCC 16.2,
Rust/Cargo 1.97, Node.js 24.18.1, Python 3.14.7, and quarterly
OpenJDK 17/21/25 updates. Important for CI pipelines: the Go
toolchain rotated — go1.24 and go1.25 (including the FIPS -openssl
variants) were removed, go1.27 was added, and go1.26 remains the
default (now 1.26.6, openssl variant 1.26.7). Pin your builders
accordingly.
6. VPN and networking modernization. OpenVPN jumps 2.6.x → 2.7.5 ,
accompanied by a new in-kernel OpenVPN Data Channel Offload module
(ovpn-kmp) for higher throughput. Also refreshed: HAProxy 3.4.4,
dhcpcd 10.5, dnsdist 2.0.7, and open-lldp . Validate OpenVPN configs
against the 2.7 series before rollout.
7. Virtualization, cloud, and management. QEMU 11.0.3 , iPXE 2.0 ,
updated Intel microcode (20260812) and Intel QAT libraries (26.02) ,
and refreshed public-cloud agents (Azure azure-vm-utils 0.7,
Google guest configs). Management tooling advances with the Agama 24
installer, SUSEConnect 1.23, RMT server 3.1 , a new Cockpit
bootloader module, and new MCP servers (mcp-server-snapper,
mcp-server-suseconnect) for AI/agent-driven administration.
8. Notable removals, plus a High Availability refresh. ProFTPD,
OpenBLAS (serial/OpenMP variants), and the fwts firmware test suite
have been dropped — audit any dependencies on these before upgrading.
On the HA side, Pacemaker moves to 3.0.3 , resource-agents and
ldirectord are promoted to the 4.18.0 final release , the full
fence-agents set is refreshed, and DRBD/corosync/kronosnet are
rebuilt with the kronosnet CVE fixes noted above.
Try it out!
RC3 is available for testing across public cloud providers, download
portals, and container registries. We encourage our user base and
partner ecosystem to deploy this candidate, validate workloads, and
report any findings through official support channels before we lock
things down for GA.
For more information about the SLES 16.1 Beta program, please visit
https://www.suse.com/betaprogram/sles16-beta .
As this is not a final release, please report bugs via bugzilla[1].
We will release the release candidates publicly and finally we plan to
release the gold version in November 2026.
Download
The following beta products are available for download:
- SUSE Linux Enterprise Server 16.1[2]
- SUSE Linux Enterprise for SAP applications 16.1[3]
- SUSE Linux Enterprise High Availability Extension 16.1[4]
SLE Beta Subscription and Registration Code
Please note that your regular SLE key will not activate the beta
environment. A special Beta Registration Code is required to access
the SUSE Linux Enterprise 16 beta online channels and repositories
within the SUSE Customer Center. Without this code, you will not be
able to access the beta content.
To obtain a Beta Registration Code and unlock your Beta Subscription,
please submit a request to beta-programs at suse.com. When
requesting, specify the desired products (SLES 16.1, SLES for SAP
16.1, SLE HA 16.1, or all) and the relevant architectures.
Documentation
Draft release notes are currently available:
- SUSE Linux Enterprise Server 16.1: susedoc.github.io/release-notes/sles-16.1/html/release-notes/
- SUSE Linux Enterprise for SAP Applications 16.1: susedoc.github.io/release-notes/slesap-16.1/html/release-note
s/[5]
- SUSE Linux Enterprise High Availability Extension 16.1: susedoc.github.io/release-notes/sleha-16.1/html/release-notes
/[6]
Draft product documentation can be found at
susedoc.github.io/#sles16
The beta allows for both online and offline installation using the
Agama installer. More details are available at
agama-project.github.io[7]
Please be aware that documentation for the beta is still under
development, and not all content is finalized or available yet.
Questions?
For additional details, please consult the dedicated Beta
webpage[8].
If you want to contact us for any inquiry, we are at your disposal via
email at beta-programs at suse.com.
The SUSE Linux Enterprise Team.
Your SUSE Linux Enterprise team
Click here to unsubscribe[9]
[1]:https://bugzilla.suse.com/enter_bug.cgi?product=SUSE%20Li
nux%20Enterprise%20Server%2016.1
[2]:https://www.suse.com/download/sles/
[3]:https://www.suse.com/download/sle-sap/
[4]:https://www.suse.com/download/sle-ha/
[5]:https://susedoc.github.io/release-notes/slesap-16.1/html/
release-notes/index.html
[6]:https://susedoc.github.io/release-notes/sleha-16.1/html/r
elease-notes/index.html
[7]:https://agama-project.github.io/
[8]:https://www.suse.com/betaprogram/sles16-beta
[9]:mailto:sle-beta-leave at lists.suse.com?subject=Unsubscribe%
20from%20SLES%20Public%20Beta%20Program&body=Unsubscribe%20fr
om%20SLES%20Public%20Beta%20Program
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-beta/attachments/20260911/bb3aa978/attachment.htm>
More information about the sle-beta
mailing list