CVE-2026-40393
published 2026-04-12CVE-2026-40393: In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
34.7th percentile
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mesa3d | mesa | < 25.3.6 | 25.3.6 |
| mesa3d | mesa | — | — |
| mesa3d | mesa | >= 26.0.0 < 26.0.1 | 26.0.1 |
| ubuntu | mesa | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w54f-pw7x-c532: In Mesa before 25
ghsa_unreviewed·2026-04-12
CVE-2026-40393 [HIGH] CWE-787 GHSA-w54f-pw7x-c532: In Mesa before 25
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
VulDB
mesa3d Mesa up to 25.3.5/26.0.0 WebGPU out-of-bounds write
vuldb·2026-04-12·CVSS 8.1
CVE-2026-40393 [HIGH] mesa3d Mesa up to 25.3.5/26.0.0 WebGPU out-of-bounds write
A vulnerability classified as critical has been found in mesa3d Mesa up to 25.3.5/26.0.0. This vulnerability affects unknown code of the component WebGPU. The manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-40393. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
Ubuntu
Mesa vulnerability
vendor_ubuntu·2026-06-15
CVE-2026-40393 Mesa vulnerability
Title: Mesa vulnerability
Summary: Mesa could be made to crash or run programs if it received specially
crafted input.
It was discovered that Mesa did not properly validate memory allocation
sizes in WebGPU under certain circumstances. An attacker could use this
issue to cause Mesa to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
No detection rules found.
No public exploits indexed.
2026-04-12
Published