CVE-2026-40393: Critical severity Mesa Mesa vulnerability
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mesato a version that resolves this vulnerability.Fixed in 26.0.8-1 - Upgrade
Upgrade
Mesato a version that resolves this vulnerability.Fixed in 25.3.6 - Upgrade
Upgrade
Mesato a version that resolves this vulnerability.Fixed in 26.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40393?
CVE-2026-40393 has a high severity due to the potential for out-of-bounds memory access.
How do I fix CVE-2026-40393?
To fix CVE-2026-40393, upgrade to Mesa version 25.3.6 or 26.0.1 or later.
What software is affected by CVE-2026-40393?
CVE-2026-40393 affects Mesa versions prior to 25.3.6 and 26.0.1.
What type of vulnerability is CVE-2026-40393?
CVE-2026-40393 is an out-of-bounds memory access vulnerability related to WebGPU.
Who is the vendor for CVE-2026-40393?
The vendor for CVE-2026-40393 is Mesa3D.