There are a number of accumulated CVE problems in libcontainer that wont be resolved unless you bump the go version to 1.24.8 or 1.25.2
Example:
https://pkg.go.dev/vuln/GO-2025-4015
GHSA-wcw9-47fp-rrfr
Also, please notice, users of falco cannot easily do this bump themselves because building falco pulls an already built binary libcontainer.so.