Executive brief
A vulnerability exists in the National Instruments NI-PAL kernel driver, a core component used by many NI hardware drivers on Windows and Linux. An authorized user on the system could exploit this flaw to crash the operating system, leading to a total loss of availability for the affected machine. This could disrupt laboratory operations, automated testing, or industrial control processes relying on NI hardware.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in the NI-PAL kernel driver due to improper input validation. The flaw is located in the nipalk.sys driver on Windows and the ni-pal kernel module on Linux. A local authenticated attacker with low privileges can provide specially crafted input to the driver to trigger a kernel panic or Blue Screen of Death (BSOD). This results in a complete denial of service of the host operating system. The vulnerability is addressed in NI-PAL version 26.3.1 (included in NI-VISA 2026 Q2 Patch 1 for Windows) and the 2026 Q2 releases for Linux and Linux Real-Time.
Affected products
- National Instruments NI-PAL 26.3.0 and prior
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory
- 2026-06-02: patched