CVE-2026-40393
EUVD-2026-2173712.04.2026, 19:16
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mesa3d | mesa | 𝑥 < 25.3.6 | CNA |
| mesa3d | mesa | 26.0.0 ≤ 𝑥 < 26.0.1 | CNA |
Debian Releases
Common Weakness Enumeration