View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-40393 severity moderate: SUSE including 136 source package names (Mesa-17.0.5-117.14.1, Mesa-18.3.2-14.12.1, …), 139 product×package rows across 10 product lines (SUSE Linux Enterprise Micro 5.2, SUSE Linux Enterprise Micro 5.3, … (10 product lines)): First Fixed 138, Fixed 1.
In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.