Local Code Execution Vulnerability in AWS FPGA Development Kit
CVE-2026-85028
7.3HIGH
What is CVE-2026-85028?
A vulnerability exists in the FPGA management tool installation component of the AWS FPGA Development Kit. This issue arises from the creation of a temporary file in a directory with insecure permissions, allowing local users to potentially execute arbitrary code with elevated privileges. The risk is particularly concerning as crafted shell content can be placed in a world-writable temporary directory, which the installation process reads after escalating its privileges. To mitigate this vulnerability, it is essential to upgrade to version 2.3.4 or later.
Affected Version(s)
aws-fpga 0 < 2.3.4
