This advisory has been withdrawn because it was incorrectly attributed to runc. Please see the issue here for more information.
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. This issue has its root in how runc handles Config Annotations lists.
{
"github_reviewed_at": "2024-04-26T22:44:51Z",
"cwe_ids": [
"CWE-77"
],
"nvd_published_at": "2024-04-26T04:15:09Z",
"github_reviewed": true,
"severity": "HIGH"
}