transmission is great if you're just getting linux images, but it's much easier to configure qbittorrent for stuff like VPN lockout and such
It's pretty easy to combine docker containers for torrenting and a VPN so that the torrenting doesn't get any network access until the VPN successfully connects. However, I use qbittorrent myself (containerised of course).
Why for Linux images only? I use it with everything. You do not even need to use the GUI, there is transmission-cli. There is transmission-daemon as well, controlled by transmission-remote (or Transmission's web interface), meaning that you can use it on a seedbox.
Without a formal audit on a variety of BT clients, this isn't really an answerable question. Just because this one issue was discovered in qBT, doesn't mean that there are hundreds more in it, and Transmission, say, has none.
The one in a restricted container.
This is exactly what I do with any software that talks to the Internet. However I'd still really, really like for an advanced adversary to not have arbitrary RCE on my machine, whether it's in a container or not. Any zero days in my kernel that said adversary may have in their back pocket are then exposed for exploitation.
Containers aren't strong security boundaries so the question still remains. If you get RCE in a containerized app you can tickle eg host kernel bugs, container runtime bugs, etc.
There are none. They connect to thousands of untrusted peers, accepts incoming connections, all in C++ code, and none of them are sandboxed. It's laughable.