A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
Credits
Red Hat would like to thank Erik Sjölund (erik.sjolund@gmail.com) for reporting this issue.