The Linux kernel has had a lot of holes in the namespace stuff used for containers, I doubt that there will not be more. Not to mention all the local root exploits, seLinux-bypass, information leaks and so on. If you're relying on Linux features for security without at least using the grsec patches, you probably already lost.