In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82646.json"