Rocky Linux 9.2 [CIQ] Security Update: httpd / httpd-core / httpd-core-debuginfo / httpd-debuginfo / etc Multiple Vulnerabilities (ciqsa-2026_1482)

critical Nessus Plugin ID 356226

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_1482 advisory.

This advisory aggregates security fixes for the httpd SRPM in CIQ LTS 9.2. It addresses 18 CVEs:
CVE-2025-58098, CVE-2025-65082, CVE-2025-66200, CVE-2026-29169, CVE-2026-34355, and 13 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_1482.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?062f2308

http://www.nessus.org/u?0b7f540b

http://www.nessus.org/u?1339db70

http://www.nessus.org/u?260d134a

http://www.nessus.org/u?36e7b615

http://www.nessus.org/u?398496a8

http://www.nessus.org/u?3bf67d4b

http://www.nessus.org/u?42a1d7c0

http://www.nessus.org/u?4a5428eb

http://www.nessus.org/u?6cdf55cc

http://www.nessus.org/u?82c36029

http://www.nessus.org/u?8e9d7381

http://www.nessus.org/u?c9c384bb

http://www.nessus.org/u?d60a00df

http://www.nessus.org/u?e5719e55

http://www.nessus.org/u?eb6d1574

http://www.nessus.org/u?f16255d2

http://www.nessus.org/u?f74bf1bb

http://www.nessus.org/u?f75461bf

Plugin Details

Severity: Critical

ID: 356226

File Name: ciq_rocky_linux_9_2_ciqsa-2026_1482.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-44631

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 12/4/2025

Reference Information

CVE: CVE-2025-58098, CVE-2025-65082, CVE-2025-66200, CVE-2026-24072, CVE-2026-28780, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631