Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40393

36
FAUCET Score

BRIEFING NOTE: CVE-2026-40393 CVE-2026-40393 is a critical out-of-bounds memory access vulnerability in Mesa's WebGPU implementation that affects versions prior to 25.3.6 and 26.0.1. The flaw arises from insufficient validation of memory allocation sizes controlled by untrusted parties, which are subsequently used in stack allocation operations, potentially enabling arbitrary code execution or system compromise. The vulnerability carries a CVSS 3.1 severity rating of 9.8 (CRITICAL) due to its network-exploitable nature requiring no authentication or user interaction. The attack has low complexity and affects system confidentiality, integrity, and availability equally. The network-accessible WebGPU interface makes this particularly concerning for systems exposing graphics processing capabilities to remote callers. Current exploitation status indicates this vulnerability is not yet being actively exploited in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive status on vulnerability hot lists. However, the moderate EPSS score of 0.0005 suggests ongoing monitoring by threat actors. Organizations should prioritize patching Mesa to 25.3.6 or later and 26.0.1 or later, particularly for systems with WebGPU exposure, pending public exploit availability.

Impacted Technologies

VendorProductVersion(s)CPE
< 25.3.6CPE matchmatch criteria
cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:*
26.0.0CPE matchmatch criteria
cpe:2.3:a:mesa3d:mesa:26.0.0:*:*:*:*:*:*:*
>= 0, < 25.3.6CPE match
cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:*
>= 26.0.0, < 26.0.1CPE match
cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 12th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: azl3 mesa 24.0.1-6 on Azure Linux 3.0Fixed in: 24.0.1-8
microsoftpatch availablevia msrc
Product: 21199-17084Fixed in: 24.0.1-8
ubuntupatch availablevia ubuntu_usn
Product: mesa (jammy)Fixed in: 23.2.1-1ubuntu3.1~22.04.4
ubuntupatch availablevia ubuntu_usn
Product: mesa (noble)Fixed in: 25.2.8-0ubuntu0.24.04.2
ubuntupatch availablevia ubuntu_usn
Product: mesa (questing)Fixed in: 25.2.8-0ubuntu0.25.10.2

Vendor Advisories (2)

ubuntuUSN-8427-1

Mesa vulnerability

Jun 15, 2026
microsoft2026-Apr/CVE-2026-40393Important

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

Apr 14, 2026

References

lists.debian.org / debian-lts-announce/2026/07/msg00021.html
gitlab.freedesktop.org / mesa/mesa/-/merge_requests/39866
Issue Tracking
lists.freedesktop.org / archives/mesa-dev/2026-February/226597.html
Issue TrackingMailing List