A flaw was found in cri-o. A malicious container can create a symbolic link pointing to an arbitrary directory or file on the host via directory traversal (??../??). This flaw allows the container to read and write to arbitrary files on the host system.