CVE-2026-40393 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: April 12, 2026
Mesa - Buffer Overflow
Published: April 12, 2026Updated: April 12, 2026Remote Exploitable
Overview
Mesa < 25.3.6 and 26 < 26.0.1 contain a buffer overflow caused by out-of-bounds memory access in WebGPU due to untrusted allocation size, letting attackers cause memory corruption, exploit requires untrusted input.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Attackers can cause memory corruption leading to potential crashes or code execution.
Mitigation
Upgrade to versions 25.3.6, 26.0.1 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-40393
- Severity
- High
- CVSS Score
- 8.1
- Type
- buffer_overflow
- Status
- new
CWE
- CWE-787
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H