CVE-2018-12293: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 10.4% chance of exploitation in the next 30 days.

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 17.10 only; version 18.04 only
  • WebKitGTK Webkitgtk+: before 2.20.3 (fixed in 2.20.3)
  • Wpewebkit Wpe Webkit: before 2.20.1 (fixed in 2.20.1)

Published 2018-06-19. Last modified 2026-06-17.