If your physical network corrupts data, TCP is supposed to notice the checksum mismatch and drop the packet, and wait for it to be retransmitted. Because of this bug, Linux's TCP implementation was not validating checksums, which allowed corrupt data to reach the application.
This requires a faulty physical network, which is rare but nowhere near nonexistent. (The kernel is not introducing corruption to these packets.)
if (skb->ip_summed == CHECKSUM_NONE && rcv->features & NETIF_F_RXCSUM)
checksum offloading is encapsulated in the rcv-features bitmap, so disabling it will hide this bug.
You can do something like this within your container to disable it (from memory, might be slightly off): $ ethtool --offload VETH_DEVICE_NAME rx off tx off $ ethtool -K VETH_DEVICE_NAME gso off
Mesos has a workaround like this in it now.