In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mesa3d Mesa
cpe:2.3:a:mesa3d:mesa:*:*:*:*:*:*:*:*
|
— |
25.3.6
|
|
Mesa3d Mesa
cpe:2.3:a:mesa3d:mesa:26.0.0:*:*:*:*:*:*:*
|
— | — |