To remediate this issue, users should upgrade to version 2.3.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4. | |
| Title | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit | |
| First Time appeared |
Aws
Aws aws-fpga |
|
| Weaknesses | CWE-379 | |
| CPEs | cpe:2.3:a:aws:aws-fpga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-fpga |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-03T18:28:05.817Z
Reserved: 2026-09-02T20:02:05.161Z
Link: CVE-2026-85028
Updated: 2026-09-03T18:27:58.386Z
Status : Received
Published: 2026-09-03T19:17:30.083
Modified: 2026-09-03T19:17:30.083
Link: CVE-2026-85028
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:30:10Z