Rocky Linux 9.2 [CIQ] Security Update: bpftool-debuginfo Multiple Vulnerabilities (ciqsa-2026_1234)

high Nessus Plugin ID 356164

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.2 host has a package installed that is affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_1234 advisory.

This advisory aggregates security fixes for the kernel SRPM in CIQ FIPS 9.2 Compliant. It addresses 26 CVEs: CVE-2024-49978, CVE-2023-53047, CVE-2024-35896, CVE-2024-36960, CVE-2023-51779, and 21 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected bpftool-debuginfo package based on the guidance in CIQ advisory ciqsa-2026_1234.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?013763ea

http://www.nessus.org/u?01e0b43a

http://www.nessus.org/u?0dea017a

http://www.nessus.org/u?17253a12

http://www.nessus.org/u?17c10a37

http://www.nessus.org/u?1a42c2e8

http://www.nessus.org/u?1d931010

http://www.nessus.org/u?21b001b5

http://www.nessus.org/u?2308a181

http://www.nessus.org/u?283a0ead

http://www.nessus.org/u?66b8d809

http://www.nessus.org/u?6c446676

http://www.nessus.org/u?773c6bb0

http://www.nessus.org/u?8b3f8be9

http://www.nessus.org/u?95b8c2d7

http://www.nessus.org/u?9af4e61e

http://www.nessus.org/u?9f94db7c

http://www.nessus.org/u?a0d33eec

http://www.nessus.org/u?abf0de13

http://www.nessus.org/u?c3e55790

http://www.nessus.org/u?cc787c34

http://www.nessus.org/u?cca75f70

http://www.nessus.org/u?e7e085bc

http://www.nessus.org/u?edc5d12f

http://www.nessus.org/u?f19af5ac

http://www.nessus.org/u?fdd99bad

http://www.nessus.org/u?ff45a466

Plugin Details

Severity: High

ID: 356164

File Name: ciq_rocky_linux_9_2_ciqsa-2026_1234.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-42284

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2022-3545, CVE-2022-41858, CVE-2023-1252, CVE-2023-2176, CVE-2023-3567, CVE-2023-4015, CVE-2023-51043, CVE-2023-51779, CVE-2023-52933, CVE-2023-53047, CVE-2023-6931, CVE-2024-26852, CVE-2024-26886, CVE-2024-35896, CVE-2024-35962, CVE-2024-36883, CVE-2024-36904, CVE-2024-36960, CVE-2024-36978, CVE-2024-41049, CVE-2024-42281, CVE-2024-42284, CVE-2024-46858, CVE-2024-49978, CVE-2025-38124, CVE-2025-38471