CVE-2026-40393Disclosure(mesa3d / mesa)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mesa3d mesa systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mesa

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mesa

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-12: 2Mentions · 2026-04-13: 1Mentions · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-08: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 104-1204-1305-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-122
Disclosure2
2026-04-131
Disclosure1
2026-05-081
Patch1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for mesa3d Mesa (CVE-2026-40393) https://vuldb.com/vuln/357042

    Post summary

    A new vulnerability, CVE-2026-40393 affecting Mesa, has been disclosed with higher severity, but no technical, exploitation, or mitigation details are provided.

    0001091
    2.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-40393 isn't going anywhere. Check your #openSUSE Mesa version, run this 1‑minute script, and lock down WebGPU for good Read more - > https://tinyurl.com/5n6hwtww #Security https://t.co/GaivOvkoAi

    Post summary

    The post presents a short script that users can run to disable WebGPU on openSUSE Mesa, effectively mitigating CVE‑2026‑40393.

    0000053
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40393 In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, … https://www.cve.org/CVERecord?id=CVE-2026-40393

    Post summary

    The post discloses CVE‑2026‑40393 as an out‑of‑bounds memory access in Mesa’s WebGPU before version 25.3.6 (and 26 before 26.0.1).

    00000113
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40393 Out-of-Bounds Memory Access in Mesa WebGPU Before 25.3.6 and 26.0... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40393 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-40393, detailing an out‑of‑bounds memory access in Mesa WebGPU before specified versions, and provides a link to additional vulnerability information, but offers no PoC, exploit, patch, or active exploitation evidence.

    0000059
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmesa3dmesa---
Appmesa3dmesa26.0.0--

Explore more