CVE-2026-20786: Medium severity Intel(R) NPU Driver vulnerability
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20786?
CVE-2026-20786 has a risk score of 23, indicating a significant potential for denial of service.
How do I fix CVE-2026-20786?
To address CVE-2026-20786, users should update the Intel(R) NPU Driver to the latest version available.
Who is affected by CVE-2026-20786?
CVE-2026-20786 affects all versions of the Intel(R) NPU Driver used by user applications.
What type of attack does CVE-2026-20786 facilitate?
CVE-2026-20786 allows an unprivileged software adversary to launch a denial of service attack.
What are the potential consequences of CVE-2026-20786?
The potential consequence of CVE-2026-20786 is an out-of-bounds read that may lead to denial of service in user applications.