Skip to content

Minor Release Upgrades

Minor release upgrades (e.g., EL 9.3 to 9.4) are the most common maintenance operation. This guide covers the complete dnf update workflow including pre-checks, execution, verification, and rollback.

Before performing an upgrade, review what packages have updates available.

Check for available updates
dnf check-update

This command returns exit code 100 when updates are available, 0 when there are none, and 1 on error.

List security-related updates only
dnf updateinfo list security
View details for a specific advisory
dnf updateinfo info --advisories=ALSA-2025:1234
View update summary statistics
dnf updateinfo summary
Perform a full system update
dnf update -y
Install only security patches
dnf update --security -y
Update while excluding certain packages
dnf update -y --exclude=kernel* --exclude=php*
Simulate update to check for dependency issues
dnf update --assumeno

Kernel updates install alongside existing kernels rather than replacing them.

View the current kernel version
uname -r
List all installed kernels
rpm -qa kernel-core | sort -V
Update only the kernel package
dnf update kernel -y

A reboot is required to use the new kernel after updating.

The needs-restarting tool determines which services or the system itself need a restart after updates.

Install dnf-plugins-core (includes needs-restarting)
dnf install -y dnf-plugins-core
Check if a full reboot is needed
needs-restarting -r

Exit code 0 means no reboot required; 1 means a reboot is needed.

List services requiring a restart
needs-restarting -s
Restart all services that need it
needs-restarting -s | xargs -I {} systemctl restart {}
View dnf transaction history
dnf history list
View details of a specific transaction
dnf history info <transaction-ID>
Undo a specific update transaction
dnf history undo <transaction-ID> -y
Rollback to state before a given transaction
dnf history rollback <transaction-ID> -y

If a new kernel causes problems, select the old kernel from the GRUB menu at boot time.

Set the default boot kernel to an older version
grubby --set-default /boot/vmlinuz-<old-version>
  1. Notify — Inform relevant teams at least 48 hours in advance
  2. Backup — Create system snapshots or back up critical data
  3. Pre-test — Validate updates in a test environment
  4. Execute — Perform updates within the maintenance window
  5. Verify — Check service status and functionality
  6. Rollback readiness — Confirm that the rollback plan is viable
Create an LVM snapshot before updating
lvcreate -s -n pre-update-snap -L 10G /dev/vg0/root
Maintenance window update script example
#!/bin/bash
set -e
echo "=== Maintenance update started: $(date) ==="
# 1. Record current state
rpm -qa --qf '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort > /root/pkg-before.txt
# 2. Perform update
dnf update -y
# 3. Record post-update state
rpm -qa --qf '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort > /root/pkg-after.txt
# 4. Show changes
echo "=== Package changes ==="
diff /root/pkg-before.txt /root/pkg-after.txt || true
# 5. Check if reboot is needed
if ! needs-restarting -r &>/dev/null; then
echo "*** System reboot required ***"
fi
echo "=== Maintenance update completed: $(date) ==="

Set Up Automatic Security Updates (Optional)

Section titled “Set Up Automatic Security Updates (Optional)”
Install and enable automatic updates
dnf install -y dnf-automatic
# Configure to only apply security updates
sed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.conf
sed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf
systemctl enable --now dnf-automatic.timer
Check the automatic update timer status
systemctl status dnf-automatic.timer