Rocky Linux 8.6 [CIQ] Security Update: nodejs-debuginfo / nodejs-debugsource / nodejs-devel / nodejs-docs / etc Multiple Vulnerabilities (ciqsa-2026_0814)

critical Nessus Plugin ID 356790

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 8.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_0814 advisory.

This advisory aggregates security fixes for the nodejs SRPM in CIQ LTS 8.6. It addresses 25 CVEs:
CVE-2020-8174, CVE-2021-35065, CVE-2021-44531, CVE-2021-44532, CVE-2021-44533, and 20 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_0814.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?1255c313

http://www.nessus.org/u?19a45ae2

http://www.nessus.org/u?1ad39a81

http://www.nessus.org/u?1d83a98b

http://www.nessus.org/u?21bd8f97

http://www.nessus.org/u?2ed65390

http://www.nessus.org/u?4c3a3e3a

http://www.nessus.org/u?52785ea3

http://www.nessus.org/u?59af4f38

http://www.nessus.org/u?65cc7616

http://www.nessus.org/u?6883b02b

http://www.nessus.org/u?6c06fec0

http://www.nessus.org/u?6c773211

http://www.nessus.org/u?7a8c9d89

http://www.nessus.org/u?7f8d9d0d

http://www.nessus.org/u?847ec3f4

http://www.nessus.org/u?8ea637ea

http://www.nessus.org/u?9a8200b8

http://www.nessus.org/u?9ff17738

http://www.nessus.org/u?aaa714d7

http://www.nessus.org/u?b4a4c465

http://www.nessus.org/u?bb8e9d05

http://www.nessus.org/u?db6193d1

http://www.nessus.org/u?e75d6525

http://www.nessus.org/u?f16001b4

http://www.nessus.org/u?f18a13a8

Plugin Details

Severity: Critical

ID: 356790

File Name: ciq_rocky_linux_8_6_ciqsa-2026_0814.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 96.01

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-8174

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2023-32002

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 6/2/2020

Reference Information

CVE: CVE-2020-8174, CVE-2021-35065, CVE-2021-44531, CVE-2021-44532, CVE-2021-44533, CVE-2021-44906, CVE-2022-0235, CVE-2022-21824, CVE-2022-24999, CVE-2022-25881, CVE-2022-25883, CVE-2022-3517, CVE-2022-35256, CVE-2022-38900, CVE-2022-43548, CVE-2022-4904, CVE-2023-23918, CVE-2023-23920, CVE-2023-30581, CVE-2023-30588, CVE-2023-30589, CVE-2023-30590, CVE-2023-32002, CVE-2023-32006, CVE-2023-32559