Executive brief
Intel's NPU (Neural Processing Unit) Driver contains a logic flaw that allows authenticated local users to crash or disrupt system availability. An unprivileged attacker with legitimate user access can trigger the vulnerability with minimal effort, rendering the system or NPU functionality unavailable until rebooted. This impacts users relying on NPU hardware acceleration for AI/ML workloads.
Technical details
The vulnerability is an improper conditions check in the Intel NPU Driver Ring 3 (user-mode) components, leading to a denial of service condition. Attack requires local access and authenticated user privileges (low complexity, no special knowledge). An attacker can send a specially crafted request that bypasses validation logic, causing a crash or system hang with high availability impact. Patches are available: Linux drivers version 1.32.0+ and Windows drivers version 32.0.100.4723+.
Affected products
- Intel NPU Driver for Linux before 1.32.0
- Intel NPU Driver for Windows before 32.0.100.4723
Timeline
- 2026-08-11: disclosed: Public advisory INTEL-SA-01456 released
- 2026-08-11: patched: Linux driver 1.32.0 and Windows driver 32.0.100.4723 released