CVE-2019-16163: High severity Oniguruma Project Oniguruma vulnerability
Last updated 25 August 2025
Other sources
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
oniguruma is vulnerable to a denial of service, caused by stack exhaustion in regcomp.c due to recursion in regparse.c. By persuading a victim to compile a specially crafted file and execute its object code, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16163?
CVE-2019-16163 is a vulnerability in Oniguruma before 6.9.3 that allows stack exhaustion due to recursion.
How severe is CVE-2019-16163?
CVE-2019-16163 has a severity rating of 7.5 (High).
What software is affected by CVE-2019-16163?
CVE-2019-16163 affects Oniguruma before version 6.9.3, Fedora versions 29 and 30, Debian Linux version 8.0, and Ubuntu Linux version 14.04.
Where can I find more information about CVE-2019-16163?
You can find more information about CVE-2019-16163 on the following references: [link1](https://github.com/kkos/oniguruma/issues/147), [link2](https://github.com/kkos/oniguruma/commit/4097828d7cc87589864fecf452f2cd46c5f37180), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1768999).
How can I fix CVE-2019-16163?
To fix CVE-2019-16163, update to Oniguruma version 6.9.3 or higher.