HomeDefectsLIN1022-23483
Acknowledged

LIN1022-23483 : Security Advisory - go - CVE-2020-29510

Created: Apr 28, 2026    Updated: May 18, 2026
Resolved Date: May 14, 2026
Found In Version: 10.22.33.24
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVEs