Withdrawn: Runc allows an arbitrary systemd property to be injected
This advisory has been withdrawn because it was incorrectly attributed to runc. Please see the issue here for more information.
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. This issue has its root in how runc handles Config Annotations lists.