Nothing new or unique
"If a management application allows users to upload pre-created disk images in non-raw formats, it can be tricked into giving the user access to arbitrary host files via the copy-on-write backing file feature ... always validate that a disk image originating from an untrusted source has no backing file set" https://libvirt.org/secureusage.html
Docker just happens to be very promiscuous with image files, so the threat is fairly significant.