Rocky Linux 9.2 [CIQ] Security Update: bpftool / kernel / kernel-64k / kernel-64k-core / kernel-64k-debug / etc Multiple Vulnerabilities (ciqsa-2026_1410)

high Nessus Plugin ID 356142

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_1410 advisory.

This advisory aggregates security fixes for the kernel SRPM in CIQ LTS 9.2. It addresses 35 CVEs:
CVE-2024-36020, CVE-2024-38615, CVE-2024-35960, CVE-2024-35890, CVE-2024-35958, and 30 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_1410.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?0846aadb

http://www.nessus.org/u?0e8f5073

http://www.nessus.org/u?230a1730

http://www.nessus.org/u?2610f015

http://www.nessus.org/u?2a0f636b

http://www.nessus.org/u?2e660fad

http://www.nessus.org/u?32966405

http://www.nessus.org/u?34c56bb8

http://www.nessus.org/u?3582fe7a

http://www.nessus.org/u?540798e2

http://www.nessus.org/u?69cf2ce1

http://www.nessus.org/u?6e88e63b

http://www.nessus.org/u?717f6cc0

http://www.nessus.org/u?7a0f3af4

http://www.nessus.org/u?7afcbf37

http://www.nessus.org/u?7ba97123

http://www.nessus.org/u?88eaeae1

http://www.nessus.org/u?8de3cb96

http://www.nessus.org/u?92e0a7c1

http://www.nessus.org/u?935cb9f9

http://www.nessus.org/u?94099bd1

http://www.nessus.org/u?9a9b0b9a

http://www.nessus.org/u?9d570021

http://www.nessus.org/u?b592b77b

http://www.nessus.org/u?b87b1773

http://www.nessus.org/u?ca095132

http://www.nessus.org/u?cb623572

http://www.nessus.org/u?ceb5bcd8

http://www.nessus.org/u?d4c54170

http://www.nessus.org/u?dc09aab7

http://www.nessus.org/u?dceabfd4

http://www.nessus.org/u?e043fa4c

http://www.nessus.org/u?e48fa541

http://www.nessus.org/u?eee9f9e3

http://www.nessus.org/u?f0eebdaf

http://www.nessus.org/u?f892f716

Plugin Details

Severity: High

ID: 356142

File Name: ciq_rocky_linux_9_2_ciqsa-2026_1410.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23216

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-26946, CVE-2024-26984, CVE-2024-26993, CVE-2024-27016, CVE-2024-27020, CVE-2024-27393, CVE-2024-35789, CVE-2024-35852, CVE-2024-35857, CVE-2024-35885, CVE-2024-35890, CVE-2024-35898, CVE-2024-35950, CVE-2024-35958, CVE-2024-35960, CVE-2024-35969, CVE-2024-36020, CVE-2024-36025, CVE-2024-36920, CVE-2024-36941, CVE-2024-38573, CVE-2024-38615, CVE-2024-40978, CVE-2025-38441, CVE-2025-68366, CVE-2025-68724, CVE-2025-71116, CVE-2026-22979, CVE-2026-22984, CVE-2026-22990, CVE-2026-23216, CVE-2026-23401, CVE-2026-43158, CVE-2026-43190, CVE-2026-46331