No.
Create a new user namespace and you have CAP_NET_RAW within your shiny new namespace.
Create a new user namespace and you have CAP_NET_RAW within your shiny new namespace.
Archlinux has user namespaces disabled, docker does not use them by default and does not allow them inside containers by default, on Ubuntu I make sure to disable kernel.unprivileged_userns_clone on all the servers I deploy to, etc.
Otherwise no one could ping from a container.
These containers are a light way to separate processes. They are not intended as a security measure to isolate malicious processes that tries to escape.