CVE-2018-12911: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • WebKitGTK Webkitgtk+: version 2.20.3 only

Published 2018-07-19. Last modified 2026-06-17.