CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-40393 — In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occu...

·Source: NIST NVD

Updated:

Executive Summary

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

Analysis

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. CVSS Score: 8.1. Published: 2026-04-12T19:16:20.797.

Indicators of Compromise (1)

CVE (1)
CVE-2026-40393
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats