GHSA-79rm-9vfm-ggwwLow

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=".

This only affects install that have the non default LDAP group provider configured. 

Users are recommended to upgrade to version 1.10.0, which fixes this issue.

🔗 References (4)