CVE-2019-19246: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 31 only
- Oniguruma Project Oniguruma: up to and including 6.9.3
- PHP PHP: from 7.3.0, before 7.3.10 (fixed in 7.3.10)
Published 2019-11-25. Last modified 2026-06-17.