CVE-2019-19246: High severity Oniguruma Project Oniguruma vulnerability
Published Aug 13, 2019
·Updated
Last updated 25 August 2025
Other sources
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in strlowercasematch in regexec.c.
Affected Software
8 affected componentsFixes available
redhat/rh-php73-php<0:7.3.20-1.el7
0:7.3.20-1.el7
redhat/oniguruma<6.9.4
6.9.4
Oniguruma Project Oniguruma<=6.9.3
PHP PHP>=7.3.0<7.3.10
Fedoraproject Fedora=31
Canonical Ubuntu Linux=14.04
Debian Debian Linux=8.0
debian/libonig
6.9.6-1.16.9.8-16.9.9-16.9.10-1
Remediation
Event History
Aug 13, 2019
CVE Published
12:00 AM
Nov 25, 2019
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·11:50 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·11:50 PM
DescriptionAffected Software
Data Sourced
via Launchpad·11:51 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is CVE-2019-19246?
CVE-2019-19246 is a vulnerability that exists in Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, which allows for a heap-based buffer over-read.
2
How does CVE-2019-19246 affect PHP?
CVE-2019-19246 affects PHP 7.3.x by causing a heap-based buffer over-read in the str_lower_case_match function in regexec.c.
3
What is the severity of CVE-2019-19246?
CVE-2019-19246 has a severity rating of 7.5 (high).
4
How can CVE-2019-19246 be fixed?
To fix CVE-2019-19246, upgrade to Oniguruma version 6.9.4 or above.
5
Where can I find more information about CVE-2019-19246?
You can find more information about CVE-2019-19246 at the following references: [1] [2] [3].