Rocky Linux 9.2 [CIQ] Security Update: thunderbird / thunderbird-debuginfo / thunderbird-debugsource Multiple Vulnerabilities (ciqsa-2026_0498)

high Nessus Plugin ID 353468

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_0498 advisory.

This advisory aggregates security fixes for the thunderbird SRPM in CIQ LTS 9.2. It addresses 61 CVEs:
CVE-2023-50761, CVE-2024-4367, CVE-2023-50762, CVE-2024-4769, CVE-2024-4770, and 56 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_0498.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?01f1ed75

http://www.nessus.org/u?0b1c385b

http://www.nessus.org/u?0de809d1

http://www.nessus.org/u?16dc8ebd

http://www.nessus.org/u?1b26fe14

http://www.nessus.org/u?1cc1314b

http://www.nessus.org/u?2429b20c

http://www.nessus.org/u?242afdc0

http://www.nessus.org/u?26a9b1c3

http://www.nessus.org/u?363bd834

http://www.nessus.org/u?3dbb2a62

http://www.nessus.org/u?3e2cfd42

http://www.nessus.org/u?411d4523

http://www.nessus.org/u?43c121c7

http://www.nessus.org/u?46ca8868

http://www.nessus.org/u?4991243d

http://www.nessus.org/u?4ad704f4

http://www.nessus.org/u?4b3dee66

http://www.nessus.org/u?4fb0560a

http://www.nessus.org/u?51d78492

http://www.nessus.org/u?5ce507a6

http://www.nessus.org/u?5d2f05ad

http://www.nessus.org/u?5fc218c4

http://www.nessus.org/u?6216313e

http://www.nessus.org/u?6367a600

http://www.nessus.org/u?64d3d1b7

http://www.nessus.org/u?69ba7797

http://www.nessus.org/u?7555ee93

http://www.nessus.org/u?76a4ab2b

http://www.nessus.org/u?855ea025

http://www.nessus.org/u?88a7c7d5

http://www.nessus.org/u?8abaaa70

http://www.nessus.org/u?8da61baa

http://www.nessus.org/u?8ea7f87b

http://www.nessus.org/u?93b6e6ca

http://www.nessus.org/u?96e287dc

http://www.nessus.org/u?a15ac62c

http://www.nessus.org/u?a854337a

http://www.nessus.org/u?a8f1981b

http://www.nessus.org/u?a91a1a87

http://www.nessus.org/u?a9ae0506

http://www.nessus.org/u?b4355ebc

http://www.nessus.org/u?b45e57df

http://www.nessus.org/u?b5dfcb1f

http://www.nessus.org/u?b63cb5b2

http://www.nessus.org/u?b6cd6fe5

http://www.nessus.org/u?b95aa0e0

http://www.nessus.org/u?b9ab8b78

http://www.nessus.org/u?bd245532

http://www.nessus.org/u?c5a8ac11

http://www.nessus.org/u?ccaa52b1

http://www.nessus.org/u?d8444a12

http://www.nessus.org/u?de0fb895

http://www.nessus.org/u?e03e90a0

http://www.nessus.org/u?e18ab3f3

http://www.nessus.org/u?e35d0f50

http://www.nessus.org/u?e6912ae7

http://www.nessus.org/u?e8427c7f

http://www.nessus.org/u?f118c62d

http://www.nessus.org/u?f8e03195

http://www.nessus.org/u?f932eff1

http://www.nessus.org/u?ff358ea5

Plugin Details

Severity: High

ID: 353468

File Name: ciq_rocky_linux_9_2_ciqsa-2026_0498.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-4777

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 11/21/2023

Reference Information

CVE: CVE-2023-50761, CVE-2023-50762, CVE-2023-5388, CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2024-0741, CVE-2024-0742, CVE-2024-0743, CVE-2024-0746, CVE-2024-0747, CVE-2024-0749, CVE-2024-0750, CVE-2024-0751, CVE-2024-0753, CVE-2024-0755, CVE-2024-1546, CVE-2024-1547, CVE-2024-1548, CVE-2024-1549, CVE-2024-1550, CVE-2024-1551, CVE-2024-1552, CVE-2024-1553, CVE-2024-1936, CVE-2024-2607, CVE-2024-2608, CVE-2024-2610, CVE-2024-2611, CVE-2024-2612, CVE-2024-2614, CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777, CVE-2024-5688, CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5696, CVE-2024-5700, CVE-2024-5702, CVE-2024-6601, CVE-2024-6602, CVE-2024-6603, CVE-2024-6604