CVE-2019-16163: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 29 only; version 30 only
- Oniguruma Project Oniguruma: before 6.9.3 (fixed in 6.9.3)
Published 2019-09-09. Last modified 2026-06-17.