User-namespace attacks TL;DR: Unprivileged namespace → CAP_SYS_ADMIN in the new namespace → various confused-deputy paths. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO