Logo
vulnerabilityCVE-2026-40393
Name
CVE-2026-40393
Source
NVD ( link)Debian ( link)
Description
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mesa3d
Patched
mesa3d-headers
Exploitable

Vulnerability Ratings#


8.1
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
26.1.3
Not Affected
buildroot
master
26.1.3
Not Affected
yocto
kirkstone
22.0.3
Exploitable
yocto
master
26.1.2
Not Affected
yocto
scarthgap
24.0.7
Exploitable

Resolved with patches#


mesa3d (buildroot:2025.02.x)

#
Title
Author
Resolve
1
spirv: Use STACK_ARRAY instead of NIR_VLA
Ian Romanick <ian.d.romanick@intel.com>
CVE-2026-40393
2
nir: Use STACK_ARRAY instead of NIR_VLA
Ian Romanick <ian.d.romanick@intel.com>
CVE-2026-40393