Vulnerability Description
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mesa3D | Mesa | < 25.3.6 |
Related Weaknesses (CWE)
References
- https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/39866Issue Tracking
- https://lists.freedesktop.org/archives/mesa-dev/2026-February/226597.htmlIssue TrackingMailing List
FAQ
What is CVE-2026-40393?
CVE-2026-40393 is a vulnerability with a CVSS score of 8.1 (HIGH). In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
How severe is CVE-2026-40393?
CVE-2026-40393 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40393?
Check the references section above for vendor advisories and patch information. Affected products include: Mesa3D Mesa.