Rocky Linux 8.6 [CIQ] Security Update: aspnetcore-runtime-6.0 / aspnetcore-targeting-pack-6.0 / dotnet / etc Multiple Vulnerabilities (ciqsa-2026_0952)

high Nessus Plugin ID 354410

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 8.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_0952 advisory.

This advisory aggregates security fixes for the dotnet6.0 SRPM in CIQ LTS 8.6. It addresses 19 CVEs:
CVE-2024-38095, CVE-2023-33128, CVE-2023-35390, CVE-2023-33170, CVE-2023-36049, and 14 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_0952.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?165ee58d

http://www.nessus.org/u?186f5bd1

http://www.nessus.org/u?1b7a1688

http://www.nessus.org/u?4c117fe2

http://www.nessus.org/u?4ef0e594

http://www.nessus.org/u?679744ee

http://www.nessus.org/u?6b520ec2

http://www.nessus.org/u?756ead6e

http://www.nessus.org/u?795629c2

http://www.nessus.org/u?79f169ef

http://www.nessus.org/u?87e013e4

http://www.nessus.org/u?949a5902

http://www.nessus.org/u?968fb307

http://www.nessus.org/u?9fae75a6

http://www.nessus.org/u?acbffc3c

http://www.nessus.org/u?b83a1d98

http://www.nessus.org/u?d71c1e0c

http://www.nessus.org/u?ec875bef

http://www.nessus.org/u?f8c0fd1a

http://www.nessus.org/u?ffb47639

Plugin Details

Severity: High

ID: 354410

File Name: ciq_rocky_linux_8_6_ciqsa-2026_0952.nasl

Version: 1.2

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

Percentile: 98.23

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-0057

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 8.7

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2024-38095

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 1/10/2023

CISA Known Exploited Vulnerability Due Dates: 8/30/2023, 10/31/2023

Reference Information

CVE: CVE-2023-21538, CVE-2023-24936, CVE-2023-29331, CVE-2023-29337, CVE-2023-32032, CVE-2023-33128, CVE-2023-33170, CVE-2023-35390, CVE-2023-36049, CVE-2023-36558, CVE-2023-36799, CVE-2023-38180, CVE-2023-44487, CVE-2024-0056, CVE-2024-0057, CVE-2024-21319, CVE-2024-21386, CVE-2024-21404, CVE-2024-38095