Christian Brauner, project leader for LXC and Incus, one of the maintainers of glibc and a contributor to the development of systemd, discovered issues in the Linux VFS (Virtual File System) kernel subsystem code that could lead to crashes, data corruption, or security problems. After identifying a problem that had gone unnoticed for five years, developer Seth Forshee from Digital Ocean fixed a bug that allowed access beyond the original namespace in which the mounting was performed, potentially leading to security issues. Fortunately, to exploit this class of vulnerabilities, the user must have privileged access, which significantly reduces the practical impact of this bug for attackers.
Source: opennet.ru