CVE-2026-40393
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
12/04/2026
Last modified:
12/04/2026
Description
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



