There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
https://www.cve.org/CVERecord?id=CVE-2021-3899
https://ubuntu.com/security/notices/USN-5427-1
https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1948376