In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 12 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. | |
| First Time appeared |
Mesa3d
Mesa3d mesa |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mesa3d
Mesa3d mesa |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-12T18:56:36.231Z
Reserved: 2026-04-12T18:49:18.544Z
Link: CVE-2026-40393
No data.
Status : Received
Published: 2026-04-12T19:16:20.797
Modified: 2026-04-12T19:16:20.797
Link: CVE-2026-40393
No data.
OpenCVE Enrichment
No data.
Weaknesses