Overview
What is CVE-2026-40393?
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Vulnerability intelligence
CVE-2026-40393 and is rated Critical severity with a CVSS score of 9.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.