Executive brief
Intel's Neural Processing Unit (NPU) Driver, a component used to interface with AI acceleration hardware on computers, contains a flaw in its firmware that can allow an authenticated user to crash the system or make it unresponsive. An attacker with local access and existing user privileges could exploit this condition-checking bug to trigger a denial of service, impacting system availability and potentially causing data loss from unexpected shutdowns.
Technical details
CVE-2026-20783 is an improper conditions check vulnerability in the firmware layer (Ring 1: Device Drivers) of Intel's NPU Driver affecting all versions. The flaw allows an authenticated local adversary with low-complexity attack requirements to trigger a denial of service condition. Attack vector is local with low attack complexity and low privileges required; no user interaction is needed. An attacker can exploit this via local access to crash or hang the system, impacting availability (high severity per CVSS). Patches are available: Linux version 1.32.0 or later and Windows version 32.0.100.4723 or later.
Affected products
- Intel NPU Driver for Linux before 1.32.0
- Intel NPU Driver for Windows before 32.0.100.4723
Timeline
- 2026-08-11: disclosed: INTEL-SA-01456 advisory published
- 2026-08-11: patched: Patches released: Linux NPU Driver 1.32.0+, Windows NPU Driver 32.0.100.4723+