Junglewise Threat Intelligence

CVE-2026-20754: Intel NPU Driver improper conditions check in firmware

CVE-2026-20754 · Severity: info · CVSS 6.9 · Published 2026-05-12

Technologies: Intel NPU Driver for Windows, Intel NPU Driver for Linux. Vendors: Intel.

Executive brief

A vulnerability in Intel NPU (Neural Processing Unit) drivers could allow a local user to crash the system. The NPU is a specialized hardware component used for accelerating artificial intelligence and machine learning tasks. An exploit could lead to a denial-of-service condition, impacting system availability and potentially disrupting ongoing operations.

Technical details

The vulnerability (CWE-754) exists due to an improper check for unusual or exceptional conditions within the firmware of Intel NPU Drivers operating at Ring 1 (Device Drivers). An unprivileged but authenticated local adversary can exploit this flaw with low complexity and no user interaction. Successful exploitation primarily impacts system availability by triggering a denial-of-service state, with a minor impact on system integrity. Intel has released updates for both Windows and Linux drivers to mitigate this issue.

Affected products

  • Intel NPU Driver for Linux before 1.26.0
  • Intel NPU Driver for Windows before 32.0.100.4511

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched

References

Related threats