Denial of Service Vulnerability in Intel NPU Drivers
CVE-2026-20754

6.9MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 May 2026

What is CVE-2026-20754?

Some Intel NPU Drivers contain a flaw due to improper conditions check within the device driver environment. This vulnerability permits an unprivileged software adversary, who has authenticated access, to execute a low-complexity attack that could lead to a denial of service. The attack can potentially occur via local access without special internal knowledge and does not require user interaction. The implications of this vulnerability may notably impact system availability, while the integrity and confidentiality remain largely unaffected.

Affected Version(s)

Intel(R) NPU Drivers See references

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.