HomeDefectsLIN1023-21144
Acknowledged

LIN1023-21144 : Security Advisory - go - CVE-2020-29510

Created: Apr 27, 2026    Updated: May 18, 2026
Resolved Date: May 14, 2026
Found In Version: 10.23.30.22
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVEs