I don't think every Linux distribution needs to aspire to be as proactive about security as OpenBSD, but it would be nice to see better care put into features like this to make sure they're restricting capabilities as expected, with at least more than one mechanism protecting the system from compromise.
Unfortunately my kneejerk reaction is to assume that most of the work on Ubuntu Server is going into development of Snap-based Ubuntu Core, wherein the security model is completely different and none of this applies, perhaps? But a ton of people deploy ordinary Ubuntu Server today, possibly more than Core... so that doesn't bode well.
(OK, maybe I really do just want OpenBSD.)
edit: Wait a minute. This post says "brand new", which made me think this was stock configuration. However, is it? I would feel immediately relieved, and my entire comment would be irrelevant, if that wasn't the case.