I'm looking into kernel exploits in recent years, approx 80% of them requires user.max_user_namespaces with a positive value.
This setting is disabled in CentOS since 6.X series, but enabled in all recent Ubuntu LTS releases.
The conclusion seems to be "Ubuntu is more easily exploitable" due to "user.max_user_namespaces" is enabled by default.
I'm wondering why won't Ubuntu disable that too? Is there any advantage to enable it in default settings?