Unprivileged pod using hostPath can side-step active LSM when it is SELinux in github.com/containerd/containerd
hostPath
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0278" }