Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mesa3d:mesa:26.0.0:*:*:*:*:*:*:* |
Mon, 13 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mesa WebGPU Out-of-bounds Memory Access Vulnerability |
Sun, 12 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. | |
| First Time appeared |
Mesa3d
Mesa3d mesa |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mesa3d
Mesa3d mesa |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-13T15:47:05.804Z
Reserved: 2026-04-12T18:49:18.544Z
Link: CVE-2026-40393
Updated: 2026-04-13T15:47:00.608Z
Status : Analyzed
Published: 2026-04-12T19:16:20.797
Modified: 2026-04-16T16:17:06.870
Link: CVE-2026-40393
No data.
OpenCVE Enrichment
Updated: 2026-04-13T12:54:03Z