To remediate this issue, users should upgrade to version 2.3.4.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4. | |
| Title | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit | |
| First Time appeared |
Aws
Aws aws-fpga |
|
| Weaknesses | CWE-379 | |
| CPEs | cpe:2.3:a:aws:aws-fpga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-fpga |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-03T18:28:05.817Z
Reserved: 2026-09-02T20:02:05.161Z
Link: CVE-2026-85028
Updated: 2026-09-03T18:27:58.386Z
Status : Received
Published: 2026-09-03T19:17:30.083
Modified: 2026-09-03T19:17:30.083
Link: CVE-2026-85028
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:30:10Z