Access to remapped root allows privilege escalation to real root · Advisory · moby/moby · GitHub
Impact When using --userns-remap, if the root user in the remapped namespace has access to the host filesystem they can modify files under /var/lib/docker/ that…