On https://support.apple.com/en-us/HT208331 there is a reference to CVE-2017-5754 with a footnote saying "Entry added January 4, 2018" (interesting to see this "changelog" being revised as the embargo has been lifted). It says the fix is "Available for: macOS High Sierra 10.13.1, macOS Sierra 10.12.6, OS X El Capitan 10.11.6"