|Index|SUSE Linux Enterprise Server Release Notes
SUSE Linux Enterprise Server 16.1

SUSE Linux Enterprise Server Release Notes

Publication Date: 2026-09-18

SUSE Linux Enterprise Server is a modern, modular operating system for both multimodal and traditional IT. This document provides a high-level overview of features, capabilities and limitations, and highlights important product updates.

1 About the release notes

These Release Notes are identical across all architectures, and the most recent version is always available online at https://www.suse.com/releasenotes.

Entries are only listed once but they can be referenced in several places if they are important and belong to more than one section.

Release notes usually only list changes that happened between two subsequent releases. Certain important entries from the release notes of previous product versions are repeated. To make these entries easier to identify, they contain a note to that effect.

However, repeated entries are provided as a courtesy only. Therefore, if you are skipping one or more service packs, check the release notes of the skipped service packs as well. If you are only reading the release notes of the current release, you could miss important changes.

1.1 Documentation and other information

For the most up-to-date version of the documentation for SUSE Linux Enterprise Server, see:

  • Find change logs for public cloud images at the Public Cloud Information Tracker (PINT) at https://pint.suse.com/.

2 What’s new?

2.1 Comparison with SUSE Linux Enterprise Server 15 SP7

To read more about the differences and high-level changes between SUSE Linux Enterprise Server 16.0 and SUSE Linux Enterprise Server 15 SP7, see these documents:

3 Support and lifecycle

SUSE Linux Enterprise Server is backed by award-winning support from SUSE, an established technology leader with a proven history of delivering enterprise-quality support services.

The current version (16.1) will be fully maintained and supported until 31 Jul 2034.

If you need additional time to design, validate and test your upgrade plans, Long Term Service Pack Support can extend the support duration. You can buy an additional 12 to 36 months in twelve month increments. This means that you can receive support up to Dec 2037.

For more information, see the pages Support Policy, Long Term Service Pack Support, and Lifecycles of SUSE Linux Enterprise Components .

3.1 Support statement for SUSE Linux Enterprise Server

To receive support, you need an appropriate subscription with SUSE. For more information, see https://www.suse.com/support/policy.html.

The following definitions apply:

L1

Problem determination, which means technical support designed to provide compatibility information, usage support, ongoing maintenance, information gathering, and basic troubleshooting using the documentation.

L2

Problem isolation, which means technical support designed to analyze data, reproduce customer problems, isolate the problem area, and provide a resolution for problems not resolved by Level 1 or prepare for Level 3.

L3

Problem resolution, which means technical support designed to resolve problems by engaging engineering to resolve product defects which have been identified by Level 2 Support.

For contracted customers and partners, SUSE Linux Enterprise Server is delivered with L3 support for all packages, except for the following:

SUSE will only support the usage of original packages. That is, packages that are unchanged and not recompiled.

3.2 General support

To learn about supported features and limitations, refer to the following sections in this document:

3.2.1 Software requiring specific contracts

Certain software delivered as part of SUSE Linux Enterprise Server may require an external contract. Check the support status of individual packages using the RPM metadata that can be viewed with rpm or zypper.

Currently, there are no major packages and groups of packages affected by this.

3.2.2 Software under GNU AGPL

SUSE Linux Enterprise Server 16.1 (and the SLE modules) includes the following software that is shipped only under a GNU AGPL software license:

  • Ghostscript (including subpackages)

  • velociraptor and velociraptor-client

  • zypp-boot-plugin

SUSE Linux Enterprise Server 16.1 (and the SLE modules) includes the following software that is shipped under multiple licenses that include a GNU AGPL software license:

  • MySpell dictionaries and LightProof

  • ArgyllCMS

3.3 Technology previews

Technology previews are packages, stacks, or features delivered by SUSE to provide glimpses into upcoming innovations. Technology previews are included for your convenience to give you a chance to test new technologies within your environment. We would appreciate your feedback! If you test a technology preview, contact your SUSE representative and let them know about your experience and use cases. Your input is helpful for future development.

Technology previews come with the following limitations:

  • Technology previews are still in development. Therefore, they may be functionally incomplete, unstable, or in other ways not suitable for production use.

  • Technology previews are not supported.

  • Technology previews may only be available for specific hardware architectures. Details and functionality of technology previews are subject to change. As a result, upgrading to subsequent releases of a technology preview may be impossible and require a fresh installation.

  • Technology previews can be removed from a product at any time. This may be the case, for example, if SUSE discovers that a preview does not meet the customer or market needs, or does not comply with enterprise standards.

3.4 SMB over QUIC support in Samba (technology preview)

The version of Samba shipped with SUSE Linux Enterprise Server 16.1 includes support for the SMB over QUIC protocol as a technology preview. This protocol enables secure and efficient access to file shares over public networks.

3.5 Boot Loader Specification (BLS) support with systemd-boot (technology preview)

SUSE Linux Enterprise Server 16.1 includes systemd-boot as a technology preview for Boot Loader Specification (BLS) support on UEFI systems.

The following limitations apply to this technology preview:

  • Available only for UEFI-based x86-64 and AArch64 architectures.

  • Not available for IBM Z, POWER, or BIOS-based systems.

  • Switching from the traditional grub2 bootloader to systemd-boot is not supported during an upgrade.

  • A fresh installation is required to use systemd-boot.

Full support is planned for a future release.

3.6 Confidential Computing Remote and Local Attestation (technology preview)

As a technology preview, remote and local attestation for AMD and Intel is available with the following packages in SUSE Linux Enterprise Server 16.1:

  • confidential-computing.sgx

  • confidential-computing.tee.dcap.pccs

  • grpcurl

  • guest-components

  • snpguest

  • snphost

  • suse-libsgx-prebuilt-signed

  • trustee

Full support is planned for a future release after validation.

4 Included packages and quarterly updates

Both the online medium and the full medium are the same for all SUSE Linux 16.1 products and only need to be downloaded once. As the full medium includes all packages of the whole SUSE Linux 16.1 family, be aware that depending on your subscription the list of packages supported by SUSE varies. You can check packages included in products on https://scc.suse.com.

Installation media, VM images and public cloud images are usually refreshed every 3 months (Quarterly Updates).

5 Supported upgrade and migration paths

SUSE Linux Enterprise Server 16.1 supports upgrading from SUSE Linux Enterprise Server 16.0, as well as migrating from preceding SUSE product releases.

  • Online (in-place) upgrade is supported from SUSE Linux Enterprise Server 16.0 (including SLES for SAP and SLE HA).

  • Offline migration (using offline installation media) is supported from:

    • SUSE Linux Enterprise Server 15 SP4, SP5, SP6, and SP7 (including SLES for SAP and SLE HA)

    • SUSE Linux Enterprise Micro 6.2

    • SUSE Linux Enterprise Real Time 15 SP7

    • openSUSE Leap 16.1

For detailed instructions, pre-upgrade checklists, and step-by-step migration procedures, see the Upgrade Guide.

6 Upgrade and migration checklist

Before upgrading to SUSE Linux Enterprise Server 16.1, review the following checklist of potential migration issues and preparation steps.

6.1 Before upgrading

6.2 During upgrade

6.3 After upgrading

7 Changes affecting all architectures

  • rasdaemon has been updated to version 0.8.4. This version supports machine checks related to CXL memory. Since Intel® Optane™ Memory products have reached End of Life (EOL), SUSE Linux Enterprise Server 16.1 does not support them either.

7.1 HAProxy and Keepalived moved to SUSE Linux Enterprise Server

Previously, only the SLE HA extension included HAProxy and Keepalived. The base SUSE Linux Enterprise Server distribution now includes both HAProxy and Keepalived. This change makes these packages available on standard installations without a separate High Availability subscription.

7.2 SLE BCI for kernel modules (Driver Toolkit)

A new Base Container Image (BCI) is now available to build and run kernel modules on SUSE Linux Enterprise Server, comparable to the upstream driver-toolkit. The container includes the necessary kernel headers for both default and RT kernels on x86_64 and aarch64 architectures, providing a simple way to prototype and test drivers without giving access to SLE kernel binaries.

7.3 SUSE Linux Enterprise Server containerdisk image now available

A SUSE Linux Enterprise Server containerdisk image is now available in the SUSE Registry (registry.suse.com). The image contains a minimal, bootable SUSE Linux Enterprise Server system in the OCI container format. Use the image to create virtual machines in cloud-native environments, for example SUSE Virtualization, Harvester, or KubeVirt.

To get the image, use the path registry.suse.com/suse/sles/16.1/containerdisk-minimal:latest.

7.4 Security update and changes in mount behavior for util-linux

An update of the util-linux package to version 2.42.2 fixes five critical security issues (CVE-2026-13595, CVE-2026-27456, CVE-2026-53612, CVE-2026-53613, CVE-2026-53614). These fixes change the behavior of mount operations for non-root processes. These changes stop privilege escalation and time-of-check-to-time-of-use (TOCTOU) race conditions.

The following changes apply:

  • Non-root mount operations must always use path canonicalization. The system ignores the X-mount.nocanonicalize option for non-root mounts.

  • Legacy mount paths reject multi-step mount sequences (such as bind+remount and propagation) for non-root mounts.

  • Non-root mounts do not support the detached subdirectory feature (X-mount.subdir).

  • Non-root mount target paths must not go through directories that unprivileged processes can write to.

If the system needs these restricted mount features, update to SUSE Linux Enterprise Server 16.2. The mountfd API in SUSE Linux Enterprise Server 16.2 uses file descriptors instead of paths, which makes operations safe against TOCTOU attacks.

For more information, see the upstream release notes at https://www.kernel.org/pub/linux/utils/util-linux/v2.42/v2.42.2-ReleaseNotes.

7.5 Increased timeout for installer boot menu

The boot menu of the live installation medium now has a timeout of 60 seconds. Previously, the timeout was ten seconds. This change provides more time to select options from the boot menu. This change does not affect the boot timeout of the installed system.

7.6 mozilla-nss favors p11-kit-nss-trust over mozilla-nss-certs by default

New installations of mozilla-nss now install p11-kit-nss-trust by default to provide libnssckbi.so. This change replaces the default installation of mozilla-nss-certs. The p11-kit-nss-trust package allows central configuration of system-wide root certificates. Firefox and other NSS consumers automatically inherit these central certificates. This avoids manual importing of enterprise certificates into individual profiles. Existing installations maintain their configuration during system upgrades. NSS static certificates remain available via the mozilla-nss-certs package and can be installed manually if required.

7.7 Reduced set of pre-built immutable system images

To simplify selection and validation, the number of pre-built immutable system images is now smaller. This release removes the Default image variant. Only the Base image variant remains available. Additionally, on the POWER architecture (ppc64le), this release removes the pre-built images for 512-byte sector sizes. Only images for 4096-byte (4 kB) sector sizes are now provided for ppc64le.

7.8 Network UPS Tools (NUT) updated to version 2.8.5

SUSE Linux Enterprise Server 16.1 updates Network UPS Tools (NUT) to version 2.8.5. This version upgrade introduces new hardware drivers, STARTTLS handling improvements, and support for name aliasing. A security patch resolves CVE-2026-54161, which prevented a potential remote command injection vulnerability in NOTIFYCMD. For a complete list of changes, see the upstream release notes.

7.9 Linux kernel BPF subsystem updated to match upstream v6.13 to v6.18

The Berkeley Packet Filter (BPF) subsystem in the Linux kernel has been updated to align with the upstream kernel versions v6.13 through v6.18.

Key changes and system requirements:

7.10 BPF tooling updated to the latest upstream versions

This release updates BPF (Berkeley Packet Filter) tooling to the latest upstream versions. The following packages are updated:

  • libbpf to version 1.6.2

  • bpftool to version 7.6.0

  • bpftrace to version 0.24.1

  • bcc to version 0.35.0, which includes the new libbpf-tools package

These updates provide new features and bug fixes.

7.11 Pressure Stall Information (PSI) enabled by default

The Pressure Stall Information (PSI) metric collection is now enabled by default. In SLES 16.0, PSI was compiled into the kernel but disabled by default (CONFIG_PSI_DEFAULT_DISABLED=y). In SLES 16.1, this default has been changed to enabled (CONFIG_PSI_DEFAULT_DISABLED=n).

Enabling PSI allows system monitoring tools (such as sysstat version 12.7.5 included in SLES 16.1) to consume global PSI values out of the box. Benchmarking shows that the performance impact of PSI is negligible for almost all workloads, including database and compute-heavy tasks. A minor performance overhead (mostly between 2% and 8%) is restricted to scheduling- and wakeup-intensive microbenchmarks.

If you encounter performance regressions on scheduling-intensive workloads, you can disable PSI at boot time by passing psi=0 to the kernel command line.

7.12 Reduced kernel lock delays during CPU restriction

High CPU load can make a container wait when it shares kernel locks. Previously, a container with CPU limits could keep a shared kernel lock when the system restricted its CPU usage. Because the container kept the lock, other containers had to wait. This waiting occurred even if the other containers had no CPU limits. The new task-based model changes this behavior. The kernel does not restrict a task when the task holds a critical lock. This change prevents delays and improves the separation of container workloads.

7.13 Coexistence of zlib and zlib-ng libraries

SUSE Linux Enterprise Server 16.1 now includes both the traditional zlib and the newer, high-performance zlib-ng compression libraries. The zlib-ng library provides substantial performance optimizations by utilizing modern CPU instruction sets. While both libraries are fully supported in this release, SUSE intends to only support zlib-ng in the future.

7.14 Unified systemd service presets between standard and immutable modes

To provide a consistent administration experience, systemd service presets have been unified between standard and immutable installation modes. As part of this unification, several standard service presets have been newly enabled by default on standard installations, including the cloud-init stack, container-image-prune.timer, kubelet.service, and others. Similarly, standard service presets such as firewalld.service, chronyd.service, gdm.service, and virtualization helpers have been enabled by default on immutable installations. Only specific presets directly related to transactional system management (such as transactional-update.timer and health-checker.service) remain restricted to their respective modes.

7.15 Distrobox pre-installed by default

SUSE Linux Enterprise Server now includes distrobox pre-installed by default, replacing the older toolbox utility. distrobox enables launching mutable, persistent containerized environments utilizing podman or docker. These environments are tightly integrated with the host system, sharing access to the home directory, external storage devices, audio and video streams, and graphical servers. This integration allows running and debugging tools from any Linux distribution directly within the terminal without modifying the underlying operating system.

7.16 NVIDIA drivers not available for real-time kernel

With the introduction of the real-time kernel in SUSE Linux Enterprise Server 16.1, some third-party kernel modules are not compatible. The NVIDIA drivers are only built for the default kernel. Consequently, NVIDIA drivers are not available when running the real-time kernel.

7.17 Repository Mirroring Tool (RMT) server now available

SUSE Linux Enterprise Server 16.1 includes the Repository Mirroring Tool (RMT) server. RMT allows mirroring of SUSE repositories and client registration inside a private network. RMT has been updated to version 3, which is compatible with Ruby 3, ensuring long-term support.

7.18 Firewalld default presets

To ensure consistent security and management preset behavior, firewalld is now enabled by default. This unification aligns the default service states across standard and immutable operating modes on SUSE Linux Enterprise Server 16.1. You can customize the firewalld presets or disable the service if necessary.

7.19 Added iptables and nftables to SLES Minimal images

The iptables and nftables packages have been added to SLES Minimal Cloud and VMware VM images. This addition enables the successful provisioning of Rancher-deployed RKE2 and K3s clusters on SLES Minimal images without requiring manual package installation or Subscription Management (RMT) registration.

7.20 Refactoring of clustering packages for Immutable Mode

SUSE Linux Enterprise Server 16.1 introduces a transactional OS option. To support this option, clustering packages have been refactored to fully comply with Immutable Mode best practices. Specifically, the file placement and RPM scriptlets for crmsh, corosync-qdevice, resource-agents, and corosync have been updated. These packages can now be safely installed and updated via the transactional-update tool. This ensures they do not attempt to write to non-transactional or non-snapshotted areas (such as /var) during transactions.

7.21 SSH public key support for all accounts created during installation

The Agama installer supports SSH public key authentication for all accounts created during installation, including the first non-root account. This eliminates the need for temporary passwords and improves post-installation security.

7.22 Automated generation and validation of Agama profiles

The Agama installer uses JSON or Jsonnet profiles for automated installations. The agama config subcommand provides capabilities to export, convert, validate, and load these profiles. For detailed instructions, command usage, and complete working examples, see the Automated Installation Using Agama guide.

7.23 SAP patterns updated

SAP installation patterns have been updated to optimize and simplify the installation process.

  • The libldap-sap-compat package is no longer included in any SAP patterns, as it is no longer required by default.

  • The libatomic package has been added to the SAP base pattern on SUSE Linux Enterprise Server to simplify the installation instructions for SAP HANA.

7.24 XFS log stripe unit alignment change

mkfs.xfs now automatically aligns the log stripe unit (lsunit) to the hardware’s reported minimum I/O size (such as a RAID controller’s stripe unit) to optimize physical disk layout. While this prevents unaligned write cycles on write-through storage devices, it may impact performance for certain types of fsync-heavy workloads on systems equipped with battery-backed or non-volatile write-back caches.

For those types of storage systems, performance can be optimized by manually setting the log stripe unit back to the block size during formatting (e.g., mkfs.xfs -l sunit=8 for 4KB). Alternatively, for highly demanding transactional workloads, utilizing a dedicated external XFS log on a non-striped device is recommended in order to entirely bypass storage layout trade-offs.

7.25 Deprecation of legacy XFS v4 filesystem format

SLE maintains backward compatibility for legacy XFS v4 filesystems via the kernel configuration CONFIG_XFS_SUPPORT_V4=y. This support ensures uninterrupted access for existing environments. However, XFS v4 is deprecated, and creating new v4 filesystems is strongly discouraged.

September 2030 is the EOL target for upstream Linux kernel support for XFS v4. Any release post-September 2030 based on updated upstream kernels will omit XFS v4 support entirely. Legacy v4 filesystems will no longer be mountable on those versions.

Upgrading underlying filesystems from v4 to v5 is transparent to applications and requires no changes to userspace software.

To check the format version of an existing XFS filesystem, run:

xfs_info /path/to/mountpoint

An output including crc=1 indicates the modern v5 format, while crc=0 indicates the legacy v4 format.

There is no in-place or online upgrade path from XFS v4 to v5. Migration requires backing up data, reformatting the block device to XFS v5, and restoring the content. Migrating the root filesystem and any other critical data partitions requires planned downtime.

The operating system generates warnings when v4 format interaction occurs:

  • mkfs.xfs displays a warning if forced to format as v4 (crc=0):

    V4 filesystems are deprecated and will not be supported by future versions
  • The kernel logs a notification upon mounting a v4 filesystem (printed once per boot cycle, upon first mount of a v4 filesystem):

    Deprecated V4 format (crc=0) will not be supported after September 2030.

7.26 Characters in the private use area disabled in the alternate German keymap

The alternate German keymap qwertz/de_alt_UTF-8 no longer supports characters in the Private Use Area (characters equal to or greater than U+F000). This change aligns the keymap with the upstream configuration and drops the custom legacy patch. Configurations that rely on custom characters mapped to this range require manual adjustment.

7.27 SDL 3 and sdl2-compat update

SUSE Linux Enterprise Server 16.1 includes Simple DirectMedia Layer 3 (SDL 3). Compatibility for SDL 2.0 applications is now provided through the sdl2-compat library layer. The legacy SDL2 package has been removed.

7.28 FreeRDP has been updated to version 3.26.0

FreeRDP has been updated to version 3.26.0. This update introduces support for FIDO2 redirection ([MS-RDPEWA]), experimental AV1 codec extension, and performance improvements for SDL3 client drawing.

7.29 Performance Co-Pilot (PCP) upgraded to version 6.3.8

Performance Co-Pilot (PCP) has been upgraded from version 6.2.0 to 6.3.8. This version upgrade introduces AMD GPU metric monitoring support in pcp-htop. It adds Valkey support alongside Redis in libpcp_web. This version upgrade also resolves multiple security vulnerabilities, including CVE-2024-45769 (bsc#1230551). For a complete list of changes, see the upstream release notes at https://pcp.io/ and the package changelog.

7.30 curl updated to version 8.21.0

SUSE Linux Enterprise Server 16.1 includes curl version 8.21.0. For a complete list of changes, see the curl 8.21.0 changelog.

7.31 PHP updated to version 8.5

SUSE Linux Enterprise Server 16.1 includes PHP version 8.5. For more information, see the PHP 8.5 release announcement and the PHP Packages Lifecycle documentation.

7.32 poppler updated to version 26.x

SUSE Linux Enterprise Server 16.1 includes the poppler PDF rendering library version 26.x.

This version update introduces several important changes for system administrators:

  • Removal of piped output filenames: For security reasons, passing a piped command as a filename parameter (for example, | command) is no longer supported in pdftops. Use standard shell pipelines instead.

  • pdfsig exit codes: The pdfsig utility now returns a non-zero exit code on signature validation failure. This may affect automated verification scripts.

  • pdftotext line endings: The pdftotext tool now defaults to \n line endings.

  • New signature features: The pdfsig utility includes a new --assert-signer option to verify the identity of the signer.

7.33 Upcoming update of GNU patch to version 2.8 in SUSE Linux Enterprise Server 16.2

The GNU patch package will be updated to version 2.8 in SUSE Linux Enterprise Server 16.2. For a complete list of upcoming changes, see the GNU patch release announcement.

GNU patch version 2.8 enforces stricter header parsing. Ensure patch-generating tools do not inject NUL bytes or raw control characters into header lines or diff directives, as they are no longer accepted in version 2.8.

7.34 Login hint when attempting root login to Cockpit

Direct root login to the Cockpit web interface is disabled by default. A login hint is now displayed upon a failed root login attempt to clarify that root access is disabled. The hint also provides instructions on logging in with a regular account, elevating privileges, or enabling root access via /etc/cockpit/disallowed-users.

7.35 Cockpit bootloader package added

SUSE Linux Enterprise Server 16.1 includes the new cockpit-bootloader package. This package provides a Cockpit interface module to configure bootloader settings. This module replaces the previous YaST bootloader configuration functionality. SUSE Linux Enterprise Server 16.1 also includes the required dependency package bootkitd.

7.36 Curated set of Ansible development and testing tools

Currently, SUSE Linux Enterprise Server ships only the Ansible runtime (ansible-core and ansible). SUSE Linux Enterprise Server 16.1 introduces a curated set of Ansible development and testing tools. These tools enable testing, linting, and building Ansible content.

The following packages are now included:

  • ansible-lint: Playbook and role linter.

  • molecule: Role and collection testing framework.

  • molecule-plugins: Test drivers (Podman, Docker, Vagrant).

  • ansible-navigator: TUI for playbook development and debugging.

  • ansible-builder: Execution environment (container image) builder.

  • ansible-runner: Ansible execution API (also a dependency of Navigator).

  • ansible-creator: Provides commands to scaffold new Ansible projects and content.

7.37 IO scheduler distribution default changed

The distribution default has changed for a certain set of block devices: rotating disks that have only a single I/O queue. On SLES, such devices would previously be driven by the bfq I/O scheduler by default. Now we are using the same default as the kernel, which is mq-deadline for most devices, and none for some.

7.38 New GCC warnings for Year 2038 (Y2K38) issues

To help identify and mitigate Year 2038 (Y2K38) 32-bit time_t rollover issues, GCC now provides new compile-time warnings. These warnings highlight legacy 32-bit timestamp interactions in C/C++ code (such as file or network I/O using int types). It is recommended to review these warnings and update affected code to use 64-bit structures where necessary.

7.39 Immutable mode is unsupported for SAP workloads

Running of the SAP software stack is not supported in immutable mode:

  • SAP-specific packages including saptune and Trento are not supported in immutable mode.

  • SAP patterns are not supported in immutable mode.

  • Ansible automation for SAP is not supported in immutable mode.

  • Execution of SAP HANA, SAP S/4HANA and SAP NetWeaver is not supported in immutable mode.

Note that this applies to traditional software. SAP software running in containers (like SAP Edge Integration Cell) is supported in immutable mode.

7.40 update-alternatives no longer used for PostgreSQL

To better support immutable systems and transactional updates, the update-alternatives mechanism is no longer used to set the default PostgreSQL version. For more details on how to set the default PostgreSQL version, refer to the README.SUSE file provided in the postgresql main package.

7.41 Agama installer supports both standard and immutable installation modes

The Agama installer supports both standard and immutable installation modes. Standard mode installs the system with a traditional read-write root directory. Immutable mode installs the system with a read-only root directory and enables transactional updates. The Agama configuration profile supports specifying the installation mode. The installation mode cannot be changed after the installation is complete.

7.42 Agama live image includes Combustion

To facilitate pre-installation configuration before launching the Agama installer, the Combustion tool is now included in the live installer image. This provides a convenient and reliable way to apply complex setups repeatedly without typing commands manually, which also covers advanced scenarios that standard graphical tools cannot handle.

Combustion does not run automatically by default. To run Combustion scripts, Combustion must be explicitly enabled by adding the rd.systemd.wants=firstboot.target boot option at the boot prompt. Ignition is not included because its configuration mechanism is unsuitable for live installer media, and Combustion is better suited for pre-installation scripting.

7.43 NVMeoF boot: network interfaces maintain standard names

For root-over-NVMeoF setups, in SLES 16.0 and prior releases, the network interfaces were renamed to nbft0, nbft1, and so on. In SLES 16.1, on new installations, network interfaces keep their standard names.

7.44 Kernel switches to PREEMPT_LAZY preemption model

The upstream kernel community has moved away from conservative scheduler preemption models (PREEMPT_NONE and PREEMPT_VOLUNTARY), and these models have been removed in kernel 7.0 for architectures that support PREEMPT_LAZY. To align with upstream changes, SUSE Linux Enterprise Server 16.1 switches the preemption model from PREEMPT_VOLUNTARY to PREEMPT_LAZY for all supported architectures, except for IBM Z (s390x), which lacks architectural support.

The PREEMPT_LAZY model provides a less conservative approach to preemption, while still being suitable for throughput-oriented workloads. If you experience performance issues with the new preemption model, you can optionally switch back to PREEMPT_VOLUNTARY by setting preempt=voluntary on the kernel command line.

7.45 Real-time kernel is available on standard SUSE Linux Enterprise Server installations

Standard SUSE Linux Enterprise Server installations now include the real-time kernel (kernel-rt). Previously, the real-time kernel was only available on systems with the Transactional Server role. All system roles now support the real-time kernel. This change provides deterministic latency and predictable execution times for standard server installations.

7.46 Stable kABI for real-time kernel

The real-time kernel (kernel-rt) now maintains a stable kernel Application Binary Interface (kABI) during maintenance updates. This stability ensures that compatible third-party kernel modules do not require recompilation for every kernel update. Note that the real-time kernel and the default kernel do not share a common kABI. Therefore, drivers built for the default kernel cannot be used with the real-time kernel and must be built separately. While SUSE aims to keep the real-time kABI stable, rare technical requirements might still require changes in future updates.

7.47 RAID configuration not supported in installer Web UI

RAID configuration is currently not supported through the installer Web UI. As a workaround, you can configure RAID either manually via the command line or by using JSON or JSONNet storage profiles. For more information, see https://agama-project.github.io/docs/user/reference/profile/storage. RAID support in the installer Web UI is planned for a future release.

7.48 Support for NTP configuration in early boot and the Agama installer

Network time synchronization is now supported during both the early boot phase and the installation process. Specifying an NTP server IP address or hostname using the new rd.ntp=<server> kernel command-line parameter enables time synchronization before the installer launches, ensuring accurate log timestamps and correct HTTPS certificate validation. The Agama installer supports NTP configuration through a dedicated ntp section in the installer profile or via input fields in the user interface. Legacy AutoYaST ntp-client configurations are automatically converted into the native ntp configuration block on profile import. The configured NTP settings are written to the target system to persist after installation.

7.49 Kiwi KubeVirt containerdisk format

Kiwi now supports a new containerdisk format for building KubeVirt-compatible container images from OEM disk builds.

The new format combines qcow2 disk image creation with OCI container packaging in a single workflow. The resulting container image contains the disk image at /disk and includes the necessary KubeVirt metadata.

The disk format (e.g. qcow2, raw, vmdk) and target container transport (e.g. docker://, oci://, obs://) are configurable via the format parameter.

Example format syntax: format="oci:qcow2:docker://registry.example.com/kubevirt-disk:latest"

7.50 SSSD: support for running as unprivileged user

SSSD has been updated to version 2.10, which adds support for running as an unprivileged user instead of root. This allows containerized deployments to comply with security requirements that limit root privileges within containers.

By default, SSSD runs as root with the sssd supplementary group, which provides access to SSSD-owned files. To switch to unprivileged mode, create a systemd service override:

sudo systemctl edit sssd.service

Add the following:

[Service]
User=sssd
Group=sssd
SupplementaryGroups=

Then reload and restart the service:

sudo systemctl daemon-reload
sudo systemctl restart sssd

Note that running as an unprivileged user requires filesystem support for POSIX capabilities. On filesystems that do not support capabilities (such as NFS), SSSD must continue to run as root.

7.51 Multiple LSMs enabled by default

SELinux is now used as the primary LSM (Linux Security Module) as compared to AppArmor that was used previously.

Apart from SELinux, we have also enabled:

  • Yama

  • Landlock

  • Lockdown

  • other virtual ones like bpf, ima, evm, capability

7.51.1 Yama

Yama is a global framework that collects system-wide DAC security protections that are not handled by the core kernel itself. Individual processes can disable Yama for themselves. The enablement of Yama disables the ptrace mechanism of processes by default, except in the following cases:

  • Processes explicitly allow it themselves via prctl(PR_SET_PTRACER).

  • The tracer is a parent of the traced process (for example, when running gdb program).

Global control is managed via the sysctl parameter /proc/sys/kernel/yama/ptrace_scope, which sits on top of standard ptrace permissions. It supports the following levels:

  • 0: Normal, classical ptrace is possible.

  • 1: Only a parent process can be traced.

  • 2: Only administrators with the CAP_SYS_PTRACE capability can use ptrace.

  • 3: No processes may be traced with ptrace. Once this level is set, a system reboot is required to enable tracing again.

To enable ptrace system-wide again after the next reboot, install the aaa_base-yama-enable-ptrace package.

7.51.2 Landlock

Landlock is a local security framework where processes can voluntarily confine their own actions. It provides scoped access-control (sandboxing) limited to file system and socket actions. Refer to the landlock manual pages for more details.

7.51.3 Lockdown

Lockdown is a kernel-based lockdown method. The kernel supports three lockdown states:

  • none

  • integrity: Maximum integrity protection, which avoids any kind of outside code injection into the kernel or physical RAM.

  • confidentiality: Same as integrity, but additionally prevents any extraction of information (even by the root user) from other processes or physical RAM.

The lockdown level can be set during boot. By default, the level is set to none, but for Secure Boot, integrity is the lowest default level. During runtime, the lockdown level can only be increased, and cannot be decreased.

7.52 Consistent location for kernel and initramfs across architectures

Previously, location of kernel or initrams would differ based on architecture.

Now these are stored in the same location regardless of architecture: boot/$arch/loader/

7.53 Supported Java Versions

The following table lists Java implementations available in SUSE Linux Enterprise Server 16.1:

Package NameVersionSupport

java-17-openjdk

17

SUSE, L3, until 2027-10-31

java-21-openjdk

21

SUSE, L3, until 2031-10-31

java-25-openjdk

25

SUSE, L3, until 2033-10-31

7.54 Python in SLES 16.1

SUSE Linux Enterprise Server 16.1 continues to use Python 3.13 as the primary Python interpreter and stack. SUSE supports the primary Python interpreter for the entire product lifecycle. This interpreter provides the default /usr/bin/python3 executable and a full stack of python3- packages (approximately 700 packages).

Additionally, SUSE Linux Enterprise Server 16.1 introduces Python 3.14 as a short-term interpreter. SUSE supports the short-term interpreter for a limited two-year lifecycle (until November 2028). This interpreter only includes the runtime and essential package management tools (setuptools, venv, pip, and pipx). It does not include the full library stack. SUSE does not provide additional python314- packages.

The Python support strategy for SUSE Linux Enterprise Server 16 introduces a new short-term interpreter with each minor version (every year). The primary Python interpreter changes every odd minor version (for example, version 3.13 in 16.0 and 16.1, and version 3.15 in 16.3 and 16.4).

8 x86-64-specific changes

Information in this section applies to the x86-64 architecture.

8.1 Clocksource watchdog disabled on HPE UV5 platforms

On HPE UV5 platforms (such as Google Compute Engine X4 bare-metal instances), the kernel clocksource watchdog previously monitored the Time Stamp Counter (TSC). This monitoring could cause system instability. Previously, preventing this instability required disabling the watchdog manually with the kernel command-line parameter tsc=nowatchdog and restarting the system. The kernel now automatically disables the clocksource watchdog for the TSC on all HPE UV5 platforms. Manual kernel parameter configuration and system restarts are no longer required.

8.2 Support for Intel "Wildcat Lake-U" CPU platform

SUSE Linux Enterprise Server 16.1 now supports Intel’s "Wildcat Lake-U" CPU platform. This hardware enablement includes updated graphics drivers for Intel Xe3 integrated graphics via the DRM kernel driver and Mesa 26.0.1. It adds device ID support for SMBus and I3C input/output interfaces. Additionally, this release enables Intel Platform Monitoring Technology (PMT) features, including Crash Log and Telemetry Aggregator, by adding the required VSEC device IDs.

9 Arm-specific changes (AArch64)

Information in this section applies to SUSE Linux Enterprise Server on Arm 16.1.

9.1 System-on-Chip driver enablement

SLES 16.1 includes driver enablement for the following System-on-Chip (SoC) chipsets:

  • Ampere* X-Gene*, eMAG*, Altra*, Altra Max, AmpereOne*

  • AWS* Graviton, Graviton2, Graviton3

  • Broadcom* BCM2837/BCM2710, BCM2711

  • Fujitsu* A64FX

  • Huawei* Kunpeng* 916, Kunpeng 920

  • Marvell* ThunderX*, ThunderX2*; OCTEON TX*; Armada* 7040, Armada 8040

  • NVIDIA* Grace; Tegra* X1, Tegra X2, Xavier*, Orin; BlueField*, BlueField-2, BlueField-3

  • NXP* i.MX 8M, 8M Mini; Layerscape* LS1012A, LS1027A/LS1017A, LS1028A/LS1018A, LS1043A, LS1046A, LS1088A, LS2080A/LS2040A, LS2088A, LX2160A

  • Rockchip RK3399, RK3588

  • Socionext* SynQuacer* SC2A11

  • Xilinx* Zynq* UltraScale*+ MPSoC

Note
Note

Driver enablement is done as far as available and requested. Refer to the following sections for any known limitations.

Some systems might need additional drivers for external chips, such as a Power Management Integrated Chip (PMIC), which may differ between systems with the same SoC chipset.

For booting, systems need to fulfill either the Server Base Boot Requirements (SBBR) or the Embedded Base Boot Requirements (EBBR), that is, the Unified Extensible Firmware Interface (UEFI) either implementing the Advanced Configuration and Power Interface (ACPI) or providing a Flat Device Tree (FDT) table. If both are implemented, the kernel will default to the Device Tree; the kernel command line argument acpi=force can override this default behavior.

Check for SUSE YES! certified systems, which have undergone compatibility testing.

9.2 Non-blocking console support

Non-blocking console (nbcon) support is enabled on the AArch64 architecture. The common AMBA PL011 serial console driver (amba-pl011) is converted to the new nbcon API. This allows the kernel to log messages atomically and reliably to the console even from non-maskable interrupt (NMI) contexts (such as during an nmi_panic). This ensures critical post-crash details are captured immediately without relying on legacy printing locks or threads.

10 IBM Z-specific changes (s390x)

Information in this section applies to SUSE Linux Enterprise Server for IBM Z and LinuxONE 16.1. For more information, see https://www.ibm.com/docs/en/linux-on-systems?topic=distributions-suse-linux-enterprise-server

10.1 New zpckey tool and changed interface in libzpc 2

SUSE Linux Enterprise Server includes libzpc version 2 for IBM Z.

The new libzpc-tools package provides the zpckey tool. Use zpckey to create and manage protected key origins, such as Secure Execution retrievable secrets. zpckey writes each key origin to a file. The OpenSSL provider module in the libzpc-provider package then reads the file. For more information, see the zpckey(1) man page.

Version 2 does not provide the libzpc C API as a shared library. Applications must use the OpenSSL provider module instead. The libzpc-legacy package provides the version 1 packages libzpc1 and libzpc-devel. The package is deprecated and will be removed in a future release.

10.2 Secure Boot support for ECKD DASD disks on IBM Z

SUSE Linux Enterprise Server now supports and automatically proposes Secure Boot during installation for ECKD DASD disks. This support is available on IBM z16, LinuxONE 4, or newer systems. The bootloader installer (zipl) automatically writes both secure boot (list-directed IPL) and non-secure boot (CCW) boot records. This ensures that the installed system remains bootable on older systems that do not support Secure Boot.

10.3 Removed support for IBM 3480 and 3590 tape drives

Support for IBM 3480 and 3590 tape drives, including the tape390_display and tape390_crypt tools, has been removed. In s390-tools, support for 3480 and 3590 FICON tape devices as well as the related tape390 utilities is removed. Other tape technologies are not affected by this removal. Virtual tape servers, such as the emulated IBM TS7700 Virtual Tape Server, continue to be supported via the tape.ko, tape_34xx.ko, and tape_3590.ko kernel modules.

10.4 Installer support for pervasive encryption on IBM Z

The Agama installer now supports pervasive encryption (PAES) for storage volumes on IBM Z. The unattended storage JSON profile supports pervasive encryption properties, such as Crypto Express APQNs and key types. The storage schema includes the new apqns and keyType properties under the pervasiveLuks2 encryption configuration. During installation, the encryption planner assigns the specified APQN objects and key types to the planned encrypted devices.

10.5 IBM z17 hardware support in libraries and development tools

Several IBM libraries and development tools now support the IBM z17 hardware platform. The system libraries libzdnn, libzpc, and libica include updates for the new hardware capabilities. Development and debugging tools, such as the GNU C Library (glibc) and Valgrind, also support the new processor instructions.

10.6 Secure Initial Program Load (IPL) support

IPL has the following minimum system requirements, depending on the boot device to be IPLed:

  • NVMe disk: IBM LinuxONE III or newer.

  • FC-attached SCSI disk: IBM LinuxONE III, IBM z15 or newer.

  • ECKD DASD with CDL layout: IBM z16, LinuxONE 4 or newer.

If these requirements are not met, the system can be IPLed in non-secure mode only.

11 POWER-specific changes (ppc64le)

Information in this section applies to SUSE Linux Enterprise Server on POWER 16.1.

11.1 Boot fails when PReP partition and root filesystem use different storage devices

On PowerVM, configuring the PReP boot partition and the root file system on different storage subsystems causes boot failures. During POST, the system firmware initializes only the boot storage subsystem, which prevents GRUB from accessing secondary devices such as SAN multipath storage.

To avoid this issue, configure the PReP boot partition and the root file system on the same storage subsystem.

11.2 Kdump capture fails on NVMe-oF targets

During kdump execution, attempting to capture a dump file to an NVMe over Fibre Channel (NVMe-FC) target on a Horton adapter fails. This issue occurs because the NVMe-FC driver maps numerous buffers for DMA, but not enough Translation Control Entries (TCEs) are freed from the Dynamic DMA Window (DDW) at kdump time. As a workaround, use Firmware-Assisted Dump (FADUMP), which is unaffected by this limitation.

11.3 Login times out on HMC virtual terminal

If you install SUSE Linux Enterprise Server 16.1 with the GNOME desktop on LPAR and try to login via the HMC virtual terminal, the login may time out while entering your credentials.

To work around this issue, disable the Plymouth graphical boot screen by appending the boot parameter plymouth.enable=0 to the kernel command line.

11.4 Automated provisioning with cloud-init in virtual machine guest images

The raw and qcow2 virtual machine guest images for the POWER architecture (ppc64le) are now built with cloud-init integration. Previously, provisioning virtual machines on KVM using these images required manual configuration steps. Automated initial guest provisioning is now fully supported.

12 Virtualization

  • iSCSI boot support is disabled in OVMF images.

12.1 Virtual persistent memory (vPMEM) in virtual machine guests

SUSE Linux Enterprise Server 16.1 supports virtual persistent memory (vPMEM) in virtual machine guests on x86-64 and ppc64le. The guest kernel detects the vPMEM regions and loads the applicable driver without manual configuration. SUSE Linux Enterprise Server does not support physical Intel* Optane* Memory.

12.2 QEMU

QEMU has been updated to version 11.0.0. For changes, see https://wiki.qemu.org/ChangeLog/11.0. For removed or deprecated features, see https://qemu-project.gitlab.io/qemu/about/removed-features.html and https://qemu-project.gitlab.io/qemu/about/deprecated.html.

12.3 libvirt

libvirt has been updated to version 12.3.0, introducing modular daemons. For details, see https://libvirt.org/news.html#v12-3-0-2026-05-02.

12.3.1 Virtual machine confinement enabled by default in libvirt

libvirt now enables confinement of virtual machines (VMs) by default using the system’s default security framework (SELinux in SUSE Linux Enterprise Server 16). This improves out-of-the-box VM isolation and security. Administrators can override this setting in /etc/libvirt/qemu.conf.

12.4 VMware

12.4.1 open-vm-tools

open-vm-tools has been updated to version 13.1.0. For details, see https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md.

12.5 Confidential Computing

12.5.1 AMD SEV-SNP packages update

AMD SEV-SNP is supported in SUSE Linux Enterprise Server 16.1. The following AMD Secure Encrypted Virtualization (SEV-SNP) tools have been updated:

For details on AMD remote and local attestation, see Section 3.6, “Confidential Computing Remote and Local Attestation (technology preview)”.

12.5.2 Intel TDX Confidential Computing

Intel TDX is supported in SUSE Linux Enterprise Server 16.1. For details on Intel TDX remote and local attestation, see Section 3.6, “Confidential Computing Remote and Local Attestation (technology preview)”.

12.6 Other tools

The following virtualization utilities have been updated:

12.6.1 virt-bridge-setup

virt-bridge-setup is a new script designed to simplify network bridge creation on a specified interface using nmcli. It replaces the automatic bridge creation previously managed by yast2 virtualization.

Important considerations:

  • It supports IPv4 only.

  • It is not intended for complex network configurations (such as VLANs or bonding); manual bridge setup is recommended for these scenarios.

  • The script must be run locally (not over a remote connection) immediately after installation and before applying any custom network configurations.

12.6.2 strace updated to version 7.1

strace has been updated to version 7.1.

This update includes the following changes:

  • The summary report (-c or --summary-only) now supports wall-clock-aware columns (wall-total, wall-min, wall-max, and wall-avg). This allows comparison of wall-clock and system CPU times in a single run.

  • The summary report now includes out-of-range system calls.

  • This update improves decoding of the sched_getattr system call.

  • The utility now decodes the FS_IOC_SHUTDOWN, PIDFD_GET_INFO, and PIDFD_GET_*_NAMESPACE ioctl commands.

  • The utility now decodes the IFLA_BR_FDB_N_LEARNED, IFLA_BR_FDB_MAX_LEARNED, and IFLA_BR_STP_MODE netlink attributes.

  • This version updates the system call constant lists for CLONE_*, FSMOUNT_*, KT_*, KVM_*, LANDLOCK_*, NETDEV_*, NL80211_*, and PIDFD_*.

  • This version adds support for Linux kernel 7.1 ioctl commands.

13 Removed and deprecated features and packages

This section lists features and packages that were removed from SUSE Linux Enterprise Server or will be removed in upcoming versions.

13.1 Removed features and packages

The following features and packages have been removed in this release.

  • SUSE Linux Enterprise Server 16.1 removes the python-python-jose and python-python-jose-cryptography packages. Upstream does not maintain these packages. You can install them from SUSE Package Hub. As an alternative, use the python-PyJWT package.

  • The libmsgpack-c2 package has been removed from SUSE Linux Enterprise Server 16.1. This package was previously required to support AMD ROCm, which is no longer planned for SUSE Linux Enterprise Server. The package has been relocated to SUSE Package Hub.

  • The python-bleach package is removed from SUSE Linux Enterprise Server 16.1. Upstream does not maintain this package. To clean HTML, use the python313-nh3 package.

  • Due to being no longer maintained, the ceph and thrift packages have been removed from SUSE Package Hub.

  • The legacy SDL2 package has been removed in favor of sdl2-compat and the newer SDL3 package. Applications relying on SDL 2.0 now utilize the sdl2-compat compatibility layer.

  • These packages have been moved to SUSE Package Hub:

    • fwts

    • python-pytest-forked

    • perl-Test-Output

    • perl-Test-Needs

    • perl-Test-Differences

  • The stress-ng package has been relocated from SUSE Linux Enterprise Server back to SUSE Package Hub. Consequently, it is no longer officially supported as part of the core product.

  • The DCCP protocol has been disabled in the SUSE Linux Enterprise Server 16.1 kernel. This protocol has been dropped from the upstream Linux kernel.

  • The UDP-Lite protocol (RFC 3828) has been disabled in the SUSE Linux Enterprise Server 16.1 kernel. This protocol has been dropped from the upstream Linux kernel.

13.1.1 Support for SUSE Rancher Prime: OS Manager 2.x removed

This release removes SUSE Rancher Prime: OS Manager 2.x components and container images. To manage operating system deployments, use SUSE Rancher Prime: OS Manager 3.x. The coexistence of versions 2.x and 3.x in the previous release supported the migration path. Only SUSE Rancher Prime: OS Manager 3.x remains supported from this release onward.

13.2 Deprecated features and packages

The following features and packages are deprecated and will be removed in a future version of SUSE Linux Enterprise Server.

  • The following SSSD features and options are deprecated in SUSE Linux Enterprise Server 16.1 and are planned for removal in SUSE Linux Enterprise Server 16.2:

    • The enumeration feature for the AD or IPA provider

    • The sss_ssh_knownhostsproxy tool

    • The files provider

    • The ad_allow_remote_domain_local_groups option

    • The default_domain_suffix option

  • Support for AF_ALG sockets (the CONFIG_CRYPTO_USER_API kernel configuration) is deprecated in SUSE Linux Enterprise Server 16.1 and will be removed in SUSE Linux Enterprise Server 16.2.

  • The packages qemu-ovmf-ia32 and qemu-uefi-aarch32 have been deprecated in SUSE Linux Enterprise Server 16.1 and will be dropped in a future release. This is because the edk2 upstream community is ending support for IA-32 and AArch32 OVMF.

  • The opa-fmgui package has been deprecated since 15 SP4 and will be removed in SLES 16.2.

  • nodejs22 has been removed.

  • The 2MB OVMF image has been removed in SUSE Linux Enterprise Server 16.1.

  • The openmpi4 package has been deprecated in SUSE Linux Enterprise Server 16.1 and will be dropped in SUSE Linux Enterprise Server 16.2.

  • The mvapich2 package has been deprecated in SUSE Linux Enterprise Server 16.1 and will be dropped in SUSE Linux Enterprise Server 16.2.

  • The dmraid package (Device-Mapper Software RAID Support Tool) has been deprecated in SUSE Linux Enterprise Server 16.1 and will be dropped in SUSE Linux Enterprise Server 16.2. Use mdadm instead to manage and monitor software RAID devices.

  • The qib driver has been deprecated in SUSE Linux Enterprise Server 16.1 and will be removed in SUSE Linux Enterprise Server 16.2.

14 Obtaining source code

This SUSE product includes materials licensed to SUSE under the GNU General Public License (GPL). The GPL requires SUSE to provide the source code that corresponds to the GPL-licensed material. The source code is available for download at https://www.suse.com/download/sles/ on Medium 2. For up to three years after distribution of the SUSE product, upon request, SUSE will mail a copy of the source code. Send requests by e-mail to sle_source_request@suse.com. SUSE may charge a reasonable fee to recover distribution costs.