CVE-2026-40393: MESA3D Mesa

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

Affected products

  • MESA3D Mesa: before 25.3.6 (fixed in 25.3.6); version 26.0.0 only

Published 2026-04-12. Last modified 2026-07-13.