Rocky Linux 8.10 [CIQ] Security Update: openssl / openssl-debuginfo / openssl-debugsource / openssl-devel / etc Multiple Vulnerabilities (ciqsa-2026_0607)

high Nessus Plugin ID 353594

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 8.10 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_0607 advisory.

This advisory aggregates security fixes for the openssl SRPM in CIQ FIPS 8.10 Compliant. It addresses 27 CVEs: CVE-2006-2937, CVE-2006-2940, CVE-2006-3738, CVE-2006-4339, CVE-2006-4343, and 22 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_0607.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?0d5eca56

http://www.nessus.org/u?1297d664

http://www.nessus.org/u?18ababb8

http://www.nessus.org/u?1916f044

http://www.nessus.org/u?2c258ea8

http://www.nessus.org/u?32cffbcb

http://www.nessus.org/u?3a65dcb4

http://www.nessus.org/u?3cafbea0

http://www.nessus.org/u?489414b2

http://www.nessus.org/u?49d11db5

http://www.nessus.org/u?4dcc9382

http://www.nessus.org/u?567f0085

http://www.nessus.org/u?58b2553f

http://www.nessus.org/u?5b737eb5

http://www.nessus.org/u?5b7afe79

http://www.nessus.org/u?5eb204d3

http://www.nessus.org/u?64fd4b3e

http://www.nessus.org/u?811e89ff

http://www.nessus.org/u?8b29b28b

http://www.nessus.org/u?9e5ed17e

http://www.nessus.org/u?a10f3123

http://www.nessus.org/u?a978440d

http://www.nessus.org/u?a9c4137e

http://www.nessus.org/u?b885348c

http://www.nessus.org/u?bb13572a

http://www.nessus.org/u?d4ab8616

http://www.nessus.org/u?ec47ce9a

http://www.nessus.org/u?ffcd8e4e

Plugin Details

Severity: High

ID: 353594

File Name: ciq_rocky_linux_8_10_ciqsa-2026_0607.nasl

Version: 1.2

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2006-3738

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2023-0286

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2020-25659

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 9/5/2006

Reference Information

CVE: CVE-2006-2937, CVE-2006-2940, CVE-2006-3738, CVE-2006-4339, CVE-2006-4343, CVE-2007-3108, CVE-2007-4995, CVE-2007-5135, CVE-2019-1547, CVE-2019-1549, CVE-2019-1563, CVE-2020-1971, CVE-2020-25659, CVE-2021-3449, CVE-2021-3450, CVE-2021-3712, CVE-2022-0778, CVE-2022-1292, CVE-2022-2068, CVE-2022-2097, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678