CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-40393 — In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occu...
·Source: NIST NVD
Updated:
Executive Summary
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Analysis
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. CVSS Score: 8.1. Published: 2026-04-12T19:16:20.797.