I don't use Docker for my containers at home, but I take it by the concern that user namespacing is not the employed by them or something?
If you're root in a namespace and manage to escape, you can have root privileges outside of it.
If you're root in a namespace and manage to escape, you can have root privileges outside of it.