Executive brief
Intel's NPU (Neural Processing Unit) Driver contains improper buffer restrictions that allow unprivileged, authenticated users to trigger a denial of service condition. An attacker can locally exploit this vulnerability with minimal complexity to crash or hang the system, impacting availability. Updates are available for both Linux and Windows versions of the driver.
Technical details
This vulnerability is a buffer handling error (improper buffer restrictions) in the Intel NPU Driver that operates in Ring 3 (user application context). The attack vector is local, requires an authenticated user, and has low attack complexity with no user interaction needed. An unprivileged process can send crafted requests that violate buffer boundaries, causing denial of service through system instability or crash. The vulnerability impacts integrity (low) and availability (high) but not confidentiality. Patches are available: version 1.32.0 or later for Linux, and version 32.0.100.4723 or later for Windows.
Affected products
- Intel NPU Driver for Linux before 1.32.0
- Intel NPU Driver for Windows before 32.0.100.4723
Timeline
- 2026-08-11: disclosed: Advisory published by Intel (INTEL-SA-01456)
- 2026-08-11: patched: Patches released: Linux v1.32.0 and Windows v32.0.100.4723