Adding this device this also appeared to fix my container that recently died. (And not simply giving it elevated privileges, as was previously recommended)
It appears that these issues all originate from an update to runc (which is used by containerd):
Luckily I realized that I could Cloudflare-tunnel my Portainer UI out to a long random-nonsense subdomain name.
That allowed me to fix it (and then immediately kill the tunnel – not a fan of exposing Portainer to the internet).