CVE-2017-18211: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • ImageMagick ImageMagick: version 7.0.7-0 only; version 7.0.7-1 only; version 7.0.7-2 only; version 7.0.7-3 only; version 7.0.7-4 only; version 7.0.7-5 only; …

Published 2018-03-01. Last modified 2026-06-17.