Qualys researchers expose ‘CrackArmor’ flaws that allow unprivileged users to escalate privileges to root, break container isolation, and crash systems, with no CVE identifiers yet assigned.
I wasn't really expecting it to just work out of the box, but NFS is surprisingly viable.