CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Cybersecurity Classified by Officially
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Bulletin ID: 2026-096-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/03/2026 11:00 AM PDT
The AWS FPGA Developer Kit is a hardware-software development kit that enables developers to create accelerators for the high-performance accelerator cards on EC2 F2 instances. We identified CVE-2026-85028, where a creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.
This issue has been addressed in AWS FPGA Developer Kit version 2.3.4. The affected code that wrote the allow_non_root function to /tmp/sdk_root_env.exp has been removed and the SDK tools now source it directly from shared/bin/set_common_functions.sh. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Remove or comment out lines referencing /tmp/sdk_root_env.exp in sdk_setup.sh and install_fpga_mgmt_tools.sh.
We would like to thank George Chen for collaborating on this issue through the coordinated vulnerability disclosure process.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-096-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
5f524987aed6d977bdadc0394ca47ea051344878