Executive brief
A vulnerability in Intel NPU (Neural Processing Unit) drivers could allow a local user to crash the system. The NPU is a specialized hardware component used for accelerating artificial intelligence and machine learning tasks. An exploit could lead to a denial-of-service condition, impacting system availability and potentially disrupting ongoing operations.
Technical details
The vulnerability (CWE-754) exists due to an improper check for unusual or exceptional conditions within the firmware of Intel NPU Drivers operating at Ring 1 (Device Drivers). An unprivileged but authenticated local adversary can exploit this flaw with low complexity and no user interaction. Successful exploitation primarily impacts system availability by triggering a denial-of-service state, with a minor impact on system integrity. Intel has released updates for both Windows and Linux drivers to mitigate this issue.
Affected products
- Intel NPU Driver for Linux before 1.26.0
- Intel NPU Driver for Windows before 32.0.100.4511
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched