CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Fpga Development ยท 2026-09-09
Actions
Technical Details
| Affected Versions | < 2.3.4 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-85028 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the AWS FPGA Development Kit to version 2.3.4 to address the security vulnerability CVE-2026-85028 and remove or comment out lines referencing /tmp/sdk_root_env.exp in sdk_setup.sh and install_fpga_mgmt_tools.sh as a temporary workaround.
For Platform Teams
Integrate the updated AWS FPGA Development Kit version 2.3.4 into the platform to enhance security and prevent potential exploitation of the identified vulnerability.
For Executives
Implement the security patch for the AWS FPGA Development Kit to mitigate the risk of arbitrary code execution with root privileges, ensuring system security and integrity.