{"id":"AZL-82688","summary":"CVE-2026-40393 affecting package mesa for versions less than 24.0.1-8","details":"In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.","modified":"2026-09-08T05:27:28Z","published":"2026-04-12T19:16:20Z","upstream":["CVE-2026-40393"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40393"}],"affected":[{"package":{"name":"mesa","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/mesa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.0.1-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82688.json"}}],"schema_version":"1.9.0"}