CVE-2026-40393:
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Score
A numerical rating that indicates how dangerous this vulnerability is.
8.1HighA numerical rating that indicates how dangerous this vulnerability is.
- Published Date:Apr 12, 2026
- CISA KEV Date:*No Data*
- Industries Affected:20
Exploitability
- Score:2.2
- Attack Vector:NETWORK
- Attack Complexity:HIGH
- Privileges Required:NONE
- User Interaction:NONE
- Scope:UNCHANGED
Impact
- Score:5.9
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:HIGH
Description Preview
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low