runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. References: https://github.com/opencontainers/runc/security/advisories/GHSA-g2j6-57v7-gm8c https://github.com/opencontainers/runc/pull/3785
Created runc tracking bugs for this issue: Affects: fedora-all [bug 2192149]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:1326 https://access.redhat.com/errata/RHSA-2023:1326