CVE-2026-78243: Apache YuniKorn can crash while processing the LDAP memberOf attribute
Security advisory dated 7 October 2026: with the LDAP group resolver configured, YuniKorn 1.8.0 through versions before 1.10.0 can crash from an out-of-bounds read. CVSS 4.0 score 2.1, low severity.
According to the advisory, published on the oss-sec feed on 7 October 2026 and identified as CVE-2026-78243, Apache YuniKorn fails when the LDAP group resolver is configured. When processing a group membership entry returned by the LDAP server in the memberOf attribute for a specified user, the component can read beyond memory bounds and crash. Affected versions range from 1.8.0 to versions before 1.10.0. The CVSS 4.0 score is 2.1, rated low, with network vector, high attack complexity and low privileges required.
To check the original, follow the advisory link given in the source on the oss-sec feed and review the affected version list in the Apache project documentation. The fix is available in version 1.10.0 or later. Rota Nacional does not run or patch YuniKorn; this item is informational for teams operating that software.