I received off list communication that the fix is here: https://github.com/apache/hadoop-common/commit/fda454
Thank you, this is the missing disclosure we were looking for.
I did not go so far back in time as >~ 21 days because the announcement was made today, so missed it.
So there is additional mitigation possible, for example, a user can patch task-controller quite readily and roll out an emergency upgrade.
Best regards,
    - Andy

Problems worthy of attack prove their worth by hitting back. - Piet Hein (via Tom White)

----- Original Message -----