A flaw was found in Podman. If an attacker can pass a crafted tar archive to the podman load command, they can create files on the host machine with the privileges of the user running Podman.
podman load
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103137.json"