This only affects install that have the non default LDAP group provider configured.
Users are recommended to upgrade to version 1.10.0, which fixes this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured. Users are recommended to upgrade to version 1.10.0, which fixes this issue. | |
| Title | Apache YuniKorn: LDAP Group provider panics on lowercase attribute name | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-07T10:13:34.935Z
Reserved: 2026-08-24T05:15:32.611Z
Link: CVE-2026-78243
No data.
Status : Received
Published: 2026-10-07T10:17:36.017
Modified: 2026-10-07T10:17:36.017
Link: CVE-2026-78243
No data.
OpenCVE Enrichment
No data.