← Vulnerability feed

Vulnerability record · CVE-2026-40393 · published 12 April 2026

CVE-2026-40393: Mesa3d mesa out-of-bounds write vulnerability

Mesa3d · Mesa

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

9.8 CVSS 3.1 Critical EPSS 0.62% · top 52.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
13 Jul 2026Last modified by NVD

Description

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-45931Mesa3d mesa null pointer dereference vulnerabilityMesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no …EPSS 1.0%6.8CVE-2013-1872Mesa3d mesa memory buffer overflow vulnerabilityThe Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly…EPSS 2.6%6.8CVE-2013-1993Mesa3d mesa vulnerabilityMultiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overfl…EPSS 2.7%6.2CVE-2023-45913Mesa3d mesa null pointer dereference vulnerabilityMesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is trigger…EPSS 0.28%5.3CVE-2023-45919Mesa3d mesa vulnerabilityMesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in …EPSS 0.39%4.4CVE-2019-5068Mesa3d mesa incorrect permission assignment vulnerabilityAn exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the…EPSS 0.48%4.3CVE-2023-45922Mesa3d mesa vulnerabilityglx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed beca…EPSS 0.54%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2026-40393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.