Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development...
UnratedCVE-2026-85028 · Published Sep 3, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software development kit that enables developers to create accelerators for the high-performance accelerator cards on EC2 F2 instances. We identified CVE-2026-85028, where a creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. Impacted versions: < 2.3.4 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs... | Unrated | No fix yet |
| Sep 4 | Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon... | Unrated | No fix yet |
| Sep 4 | Unverified access point ownership in Amazon EFS CSI Driver | Unrated | No fix yet |
| Sep 4 | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server | Unrated | No fix yet |
| Sep 3 | OS command injection in the Amazon CodeCatalyst blueprints SDK | Unrated | No fix yet |
| Sep 2 | Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 | Unrated | No fix yet |