That's pretty interesting. Does it mean it allows escaping Docker containers if you compromise a service ran as root in it?
These containers are a light way to separate processes. They are not intended as a security measure to isolate malicious processes that tries to escape.
Otherwise no one could ping from a container.