runc is a CLI tool for spawning and running containers according to the OCI specification.
Security Fix(es):
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.(CVE-2024-3154)
{
"severity": "High"
}