Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.
To remediate this issue, users should upgrade to version 2.3.4.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4. | |
| Title | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit | |
| First Time appeared |
Aws
Aws aws-fpga |
|
| Weaknesses | CWE-379 | |
| CPEs | cpe:2.3:a:aws:aws-fpga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-fpga |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-03T18:28:05.817Z
Reserved: 2026-09-02T20:02:05.161Z
Link: CVE-2026-85028
Updated: 2026-09-03T18:27:58.386Z
Status : Received
Published: 2026-09-03T19:17:30.083
Modified: 2026-09-03T19:17:30.083
Link: CVE-2026-85028
No data.
OpenCVE Enrichment
No data.