CVE-2019-13224: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Oniguruma Project Oniguruma: version 6.9.2 only
  • PHP PHP: from 7.1.0, before 7.1.32 (fixed in 7.1.32); from 7.2.0, before 7.2.23 (fixed in 7.2.23); from 7.3.0, before 7.3.9 (fixed in 7.3.9)

Published 2019-07-10. Last modified 2026-06-17.