mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0914" }