Yes, there are. The following actions are prohibited:
- Modifying the running kernel by direct access and loading kernel mod82 rules (for OpenVZ VPSs).
- Mounting and unmounting file systems (for OpenVZ VPSs).
- Accessing raw, divert, or routing sockets.
- Modifying kernel runtime parameters, such as most sysctl settings (for OpenVZ VPSs).
- Changing secure level related file flags.
- Accessing network resources not associated with the jail (for OpenVZ VPSs).