{"id":"CVE-2017-9226","details":"An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write or read occurs in next_state_val() during regular expression compilation. Octal numbers larger than 0xff are not handled correctly in fetch_token() and fetch_token_in_cc(). A malformed regular expression containing an octal number in the form of '\\700' would produce an invalid code point value larger than 0xff in next_state_val(), resulting in an out-of-bounds write memory corruption.","modified":"2026-08-07T14:53:50.316731Z","published":"2017-05-24T15:29:00.277Z","related":["SUSE-SU-2017:1585-1","SUSE-SU-2017:1662-1","SUSE-SU-2017:1717-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101244"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"REPORT","url":"https://github.com/kkos/oniguruma/issues/55"},{"type":"FIX","url":"https://github.com/kkos/oniguruma/commit/b4bf968ad52afe14e60a2dc8a95d3555c543353a"},{"type":"FIX","url":"https://github.com/kkos/oniguruma/commit/f015fbdd95f76438cd86366467bb2b39870dd7c6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kkos/oniguruma","events":[{"introduced":"c4ce370f5754b34321c7f87cdc6f198864221eca"},{"last_affected":"c4ce370f5754b34321c7f87cdc6f198864221eca"},{"fixed":"b4bf968ad52afe14e60a2dc8a95d3555c543353a"},{"fixed":"f015fbdd95f76438cd86366467bb2b39870dd7c6"}],"database_specific":{"cpe":"cpe:2.3:a:oniguruma_project:oniguruma:6.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.2.0"},{"last_affected":"6.2.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["6.2.0","v6.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9226.json","vanir_signatures_modified":"2026-08-07T14:53:50Z","vanir_signatures":[{"source":"https://github.com/kkos/oniguruma/commit/f015fbdd95f76438cd86366467bb2b39870dd7c6","target":{"file":"src/regparse.c"},"deprecated":false,"digest":{"line_hashes":["340282246448782130687958519807593876335","19691577292326266259481888258337573200","285750249724714625561365284898613084533","290219382971341702585136164131101210587","216387815878479387550531275983473066368","174739561935101457874745057573467750982","311901103716194130129169947058170981802","290219382971341702585136164131101210587"],"threshold":0.9},"id":"CVE-2017-9226-03e1ab44","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/b4bf968ad52afe14e60a2dc8a95d3555c543353a","target":{"file":"src/regparse.c"},"deprecated":false,"digest":{"line_hashes":["246829258880076191915156482018696757530","223947624233669634426607050500944957916","160761884261585877422819118548410376246","223713518639165331567966595224563676527"],"threshold":0.9},"id":"CVE-2017-9226-4c23b0ba","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/b4bf968ad52afe14e60a2dc8a95d3555c543353a","target":{"file":"src/regparse.c","function":"next_state_val"},"deprecated":false,"digest":{"function_hash":"237816653384729961923500547356155140782","length":1647},"id":"CVE-2017-9226-af653b09","signature_type":"Function"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"fixed":"de96a08a90e480f1afb655bcfeac8ac28a14228e"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"fixed":"8a79ce6c8b9d309573993ce332f3951ea1947e2f"},{"introduced":"0221e9f827632942225586687a33cfd554860d5e"},{"fixed":"73915a2bd61f21fd809b4d50af9aba950f43e807"}],"database_specific":{"cpe":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.31"},{"introduced":"7.0.0"},{"fixed":"7.0.21"},{"introduced":"7.1.0"},{"fixed":"7.1.7"}],"source":"CPE_RANGE"}}],"versions":["php-7.1.7RC1","php-7.0.21RC1","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9226.json","vanir_signatures_modified":"2026-08-07T14:53:50Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/php/php-src/commit/73915a2bd61f21fd809b4d50af9aba950f43e807","target":{"file":"ext/pcre/pcrelib/pcre_jit_compile.c","function":"compile_bracket_matchingpath"},"deprecated":false,"digest":{"function_hash":"233037532068098537505988791132617368492","length":13872},"id":"CVE-2017-9226-343f4c1a"},{"id":"CVE-2017-9226-cfd9dfdb","signature_type":"Line","signature_version":"v1","source":"https://github.com/php/php-src/commit/73915a2bd61f21fd809b4d50af9aba950f43e807","target":{"file":"ext/pcre/pcrelib/pcre_jit_compile.c"},"deprecated":false,"digest":{"line_hashes":["41612049881914751775057704412356952022","206133687184829194312361432760839012982","60469889591596012334583203454317370370","317056786488417399517652373716894105276"],"threshold":0.9}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}