rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in runc in github.com/opencontainers/runc
/sys/fs/cgroup
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1682" }