Ubuntu has the exact same vulnerability, except with lxd instead of docker, but for some reason, it's considered working as intended.
On a fresh install of Ubuntu Server, the first user created is part of the lxd group, can install lxd without root thanks to snap, and can immediately create a privileged container with the host's root filesystem mounted inside.