CVE-2026-40393

HIGH

Mesa < 25.3.6 - Out-of-Bounds Access

Title source: rule
STIX 2.1

Description

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

Scores

CVSS v3 8.1
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (4)
mesa3d/mesa 26.0.0
mesa3d/Mesa < 25.3.6
mesa3d/mesa < 25.3.6
mesa3d/Mesa 26.0.0 - 26.0.1
Published Apr 12, 2026
Tracked Since Apr 13, 2026