 > Fixes the following security issue:
 > - CVE-2020-15257: Access controls for the shim’s API socket verified that
 >   the connecting process had an effective UID of 0, but did not otherwise
 >   restrict access to the abstract Unix domain socket.  This would allow
 >   malicious containers running in the same network namespace as the shim,
 >   with an effective UID of 0 but otherwise reduced privileges, to cause new
 >   processes to be run with elevated privileges.

 > For more details, see the advisory:
 > https://github.com/containerd/containerd/security/advisories/GHSA-36xw-fx78-c5r4

