The security tracker says the cve is up to 8.29 and we have a newer version.
The fix is just documentation (to not use chown with -R -L).
https://security-tracker.debian.org/tracker/CVE-2017-18018
https://github.com/coreutils/coreutils/commit/bc2fd9796403e03bb757b064d44c22fab92e6842