A story of Docker, QEMU, and memfd_create()
This smells like possible security vulnerability. If Docker is passing environment variables meant for the container to the emulator too, there is probably a way to get Qemu to do more unintended things.
i feel sorry for people who uses docker.
falling for marketing or non critical group thinking, and then learning of their bad choices piecemeal for years on