> the primary mitigation is still patching the node kernel; user namespaces are blast-radius reduction, not a complete mitigation for this path