HomeDefectsLIN1024-16768
Acknowledged

LIN1024-16768 : Security Advisory - go - CVE-2020-29510

Created: Apr 27, 2026    Updated: May 18, 2026
Resolved Date: May 14, 2026
Found In Version: 10.24.33.17
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVEs