Junglewise Threat Intelligence

CVE-2026-20783: Intel NPU Driver improper conditions check in firmware

CVE-2026-20783 · Severity: medium · CVSS 6.1 · Published 2026-08-11

Technologies: Intel NPU Driver for Windows, Intel NPU Driver for Linux. Vendors: Intel.

Executive brief

Intel's Neural Processing Unit (NPU) Driver, a component used to interface with AI acceleration hardware on computers, contains a flaw in its firmware that can allow an authenticated user to crash the system or make it unresponsive. An attacker with local access and existing user privileges could exploit this condition-checking bug to trigger a denial of service, impacting system availability and potentially causing data loss from unexpected shutdowns.

Technical details

CVE-2026-20783 is an improper conditions check vulnerability in the firmware layer (Ring 1: Device Drivers) of Intel's NPU Driver affecting all versions. The flaw allows an authenticated local adversary with low-complexity attack requirements to trigger a denial of service condition. Attack vector is local with low attack complexity and low privileges required; no user interaction is needed. An attacker can exploit this via local access to crash or hang the system, impacting availability (high severity per CVSS). Patches are available: Linux version 1.32.0 or later and Windows version 32.0.100.4723 or later.

Affected products

  • Intel NPU Driver for Linux before 1.32.0
  • Intel NPU Driver for Windows before 32.0.100.4723

Timeline

  • 2026-08-11: disclosed: INTEL-SA-01456 advisory published
  • 2026-08-11: patched: Patches released: Linux NPU Driver 1.32.0+, Windows NPU Driver 32.0.100.4723+

References

Related threats