Out-of-Bounds Memory Access in Mesa WebGPU Product by Mesa
CVE-2026-40393

8.1HIGH

Key Information:

Vendor

Mesa3d

Status
Vendor
CVE Published:
12 April 2026

What is CVE-2026-40393?

A vulnerability in Mesa's WebGPU can lead to out-of-bounds memory access, potentially allowing malicious actors to exploit the way memory allocations are handled, as the size of the data to be allocated is influenced by untrusted input. This flaw can lead to unpredictable behavior, including crashes or unauthorized data access, highlighting the importance of careful input validation in memory management strategies.

Affected Version(s)

Mesa 0 < 25.3.6

Mesa 26.0.0 < 26.0.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.