We've been asked a few times whether the Enhance per-website containerisation offers any protection from this.
It's true that escalation to root by a customer or through a compromised CMS (WordPress, etc) would be limited to the website container. However it could potentially be chained with a different exploit to allow breakout from the container. Or a different remote code execution bug in a non-Enhance service (for example in Apache) could be used to deliver the local privilege escalation payload.
Therefore this exploit and other similar exploits should be handled with the utmost urgency by applying the mitigation and updating to the latest kernel as soon as it is released by Ubuntu.