Logo
vulnerabilityCVE-2026-40393
Name
CVE-2026-40393
Source
NVD ( link)Debian ( link)
Description
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mesa
Exploitable

Vulnerability Ratings#


8.1
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
24.0.9
Patched
buildroot
2025.02.x
24.0.9
Exploitable
buildroot
master
26.1.3
Not Affected
buildroot
master
26.1.3
Not Affected
yocto
kirkstone
22.0.3
Exploitable
yocto
master
26.1.2
Not Affected

Resolved with patches#


mesa3d (buildroot:2025.02.x)

#
Title
Author
Resolve
1
spirv: Use STACK_ARRAY instead of NIR_VLA
Ian Romanick <ian.d.romanick@intel.com>
CVE-2026-40393
2
nir: Use STACK_ARRAY instead of NIR_VLA
Ian Romanick <ian.d.romanick@intel.com>
CVE-2026-40393