BRIEFING NOTE: CVE-2026-40393 CVE-2026-40393 is a critical out-of-bounds memory access vulnerability in Mesa's WebGPU implementation that affects versions prior to 25.3.6 and 26.0.1. The flaw arises from insufficient validation of memory allocation sizes controlled by untrusted parties, which are subsequently used in stack allocation operations, potentially enabling arbitrary code execution or system compromise. The vulnerability carries a CVSS 3.1 severity rating of 9.8 (CRITICAL) due to its network-exploitable nature requiring no authentication or user interaction. The attack has low complexity and affects system confidentiality, integrity, and availability equally. The network-accessible WebGPU interface makes this particularly concerning for systems exposing graphics processing capabilities to remote callers. Current exploitation status indicates this vulnerability is not yet being actively exploited in the wild, as evidenced by its absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive status on vulnerability hot lists. However, the moderate EPSS score of 0.0005 suggests ongoing monitoring by threat actors. Organizations should prioritize patching Mesa to 25.3.6 or later and 26.0.1 or later, particularly for systems with WebGPU exposure, pending public exploit availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.3.6CPE matchmatch criteria | cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:* | ||
26.0.0CPE matchmatch criteria | cpe:2.3:a:mesa3d:mesa:26.0.0:*:*:*:*:*:*:* | ||
>= 0, < 25.3.6CPE match | cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:* | ||
>= 26.0.0, < 26.0.1CPE match | cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.