This advisory has been withdrawn because it was incorrectly attributed to runc. Please see the issue here for more information.
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. This issue has its root in how runc handles Config Annotations lists.
{ "nvd_published_at": "2024-04-26T04:15:09Z", "cwe_ids": [ "CWE-77" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-26T22:44:51Z" }