Check your privilege: CoreOS's container tech rkt gets priv-escalation defense on Intel chips
CoreOS's Linux container manager rkt - pronounced "rock-it" for those willing to pay for a few vowels - can now defend against privilege escalation attacks on virtual machines hosting Intel Clear Containers."