Rocky Linux 9.2 [CIQ] Security Update: bpftool / bpftool-debuginfo Multiple Vulnerabilities (ciqsa-2026_1217)

high Nessus Plugin ID 354748

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_1217 advisory.

This advisory aggregates security fixes for the kernel SRPM in CIQ LTS 9.2. It addresses 39 CVEs:
CVE-2025-38464, CVE-2023-53354, CVE-2023-52628, CVE-2024-36883, CVE-2024-38538, and 34 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_1217.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?013763ea

http://www.nessus.org/u?0869ce87

http://www.nessus.org/u?0f042d08

http://www.nessus.org/u?103ea04a

http://www.nessus.org/u?13beb7db

http://www.nessus.org/u?1a42c2e8

http://www.nessus.org/u?1d931010

http://www.nessus.org/u?283a0ead

http://www.nessus.org/u?2eda8170

http://www.nessus.org/u?392a5bee

http://www.nessus.org/u?3d0a9168

http://www.nessus.org/u?3f15a80e

http://www.nessus.org/u?4b5bbd83

http://www.nessus.org/u?4d4d1332

http://www.nessus.org/u?52da0a79

http://www.nessus.org/u?5d6adaa3

http://www.nessus.org/u?67cfdbe2

http://www.nessus.org/u?773c6bb0

http://www.nessus.org/u?7f82d770

http://www.nessus.org/u?801508da

http://www.nessus.org/u?8a996b0d

http://www.nessus.org/u?90e31710

http://www.nessus.org/u?94a9db10

http://www.nessus.org/u?9971b133

http://www.nessus.org/u?9af4e61e

http://www.nessus.org/u?a6d4eb24

http://www.nessus.org/u?abf0de13

http://www.nessus.org/u?bc973108

http://www.nessus.org/u?c3e55790

http://www.nessus.org/u?cb4e5cd3

http://www.nessus.org/u?cc787c34

http://www.nessus.org/u?cca75f70

http://www.nessus.org/u?cfb6ff0f

http://www.nessus.org/u?d2520802

http://www.nessus.org/u?d6915f40

http://www.nessus.org/u?f19af5ac

http://www.nessus.org/u?f2b46b1d

http://www.nessus.org/u?f50fe3ab

http://www.nessus.org/u?f61e959b

http://www.nessus.org/u?f88a8c73

Plugin Details

Severity: High

ID: 354748

File Name: ciq_rocky_linux_9_2_ciqsa-2026_1217.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38464

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 11/4/2020

Reference Information

CVE: CVE-2021-47505, CVE-2022-49840, CVE-2023-1252, CVE-2023-2176, CVE-2023-3567, CVE-2023-52628, CVE-2023-52707, CVE-2023-52973, CVE-2023-53100, CVE-2023-53354, CVE-2023-6606, CVE-2023-6610, CVE-2023-6931, CVE-2023-6932, CVE-2024-26852, CVE-2024-36883, CVE-2024-36904, CVE-2024-36978, CVE-2024-38538, CVE-2024-41049, CVE-2024-42285, CVE-2024-46858, CVE-2024-47696, CVE-2025-21727, CVE-2025-21764, CVE-2025-21867, CVE-2025-22058, CVE-2025-22113, CVE-2025-22121, CVE-2025-38000, CVE-2025-38079, CVE-2025-38107, CVE-2025-38159, CVE-2025-38177, CVE-2025-38211, CVE-2025-38350, CVE-2025-38380, CVE-2025-38464, CVE-2025-38471