Rocky Linux 9.6 [CIQ] Security Update: php / php-bcmath / php-cli / php-common / php-dba / php-dbg / etc Multiple Vulnerabilities (ciqsa-2026_1587)

critical Nessus Plugin ID 363404

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_1587 advisory.

This advisory aggregates security fixes for the php SRPM in CIQ LTS 9.6. It addresses 28 CVEs:
CVE-2024-8925, CVE-2024-8927, CVE-2025-1217, CVE-2012-2386, CVE-2012-1823, and 23 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_1587.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?0021d21c

http://www.nessus.org/u?0c186274

http://www.nessus.org/u?1043e5c3

http://www.nessus.org/u?1ba0d6c5

http://www.nessus.org/u?1ed16ce0

http://www.nessus.org/u?2bb3bc65

http://www.nessus.org/u?2e63a5ff

http://www.nessus.org/u?3913ed0e

http://www.nessus.org/u?3bbdd0a2

http://www.nessus.org/u?476d755d

http://www.nessus.org/u?4ac3c9f9

http://www.nessus.org/u?4c97eeae

http://www.nessus.org/u?5590b6f4

http://www.nessus.org/u?68f30892

http://www.nessus.org/u?6b444d8a

http://www.nessus.org/u?7daaa9b9

http://www.nessus.org/u?819b8c04

http://www.nessus.org/u?8d74e86c

http://www.nessus.org/u?8dbd70a4

http://www.nessus.org/u?94658daa

http://www.nessus.org/u?9bc04c0e

http://www.nessus.org/u?9c054e3b

http://www.nessus.org/u?9c31c82c

http://www.nessus.org/u?b06f7daf

http://www.nessus.org/u?c0b6699e

http://www.nessus.org/u?dba046cd

http://www.nessus.org/u?e441b309

http://www.nessus.org/u?e49408c4

http://www.nessus.org/u?edb7ec76

Plugin Details

Severity: Critical

ID: 363404

File Name: ciq_rocky_linux_9_6_ciqsa-2026_1587.nasl

Version: 1.1

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.83

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2013-6420

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2026-6722

CVSS v4

Risk Factor: Critical

Base Score: 9.5

Threat Score: 9.5

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2026-6722

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 4/22/2011

CISA Known Exploited Vulnerability Due Dates: 4/15/2022

Reference Information

CVE: CVE-2011-4718, CVE-2012-1823, CVE-2012-2143, CVE-2012-2311, CVE-2012-2329, CVE-2012-2386, CVE-2013-1635, CVE-2013-1643, CVE-2013-4113, CVE-2013-4248, CVE-2013-6420, CVE-2014-0185, CVE-2022-31629, CVE-2024-11233, CVE-2024-11234, CVE-2024-2756, CVE-2024-3096, CVE-2024-5458, CVE-2024-8925, CVE-2024-8927, CVE-2024-8929, CVE-2024-9026, CVE-2025-1217, CVE-2025-1219, CVE-2025-1734, CVE-2025-1736, CVE-2025-1861, CVE-2026-6722