CVE-2017-16612: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.

libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only; version 17.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • X Libxcursor: up to and including 1.1.14

Published 2017-12-01. Last modified 2026-06-17.