The flaw (CVE-2020-15157) is located in the container image-pulling process.
Source: Threadpost