CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit

Fpga Development ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions < 2.3.4
Regions all
CVE IDs CVE-2026-85028
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update the AWS FPGA Development Kit to version 2.3.4 to address the security vulnerability CVE-2026-85028 and remove or comment out lines referencing /tmp/sdk_root_env.exp in sdk_setup.sh and install_fpga_mgmt_tools.sh as a temporary workaround.

For Platform Teams

Integrate the updated AWS FPGA Development Kit version 2.3.4 into the platform to enhance security and prevent potential exploitation of the identified vulnerability.

For Executives

Implement the security patch for the AWS FPGA Development Kit to mitigate the risk of arbitrary code execution with root privileges, ensuring system security and integrity.

Source

View original AWS announcement โ†’

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.