HomeDefectsLIN1025-9432
Acknowledged

LIN1025-9432 : Security Advisory - go - CVE-2020-29510

Created: Apr 23, 2026    Updated: May 18, 2026
Resolved Date: May 14, 2026
Found In Version: 10.25.33.9
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Userspace

Description

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVEs