True. From the chroot(2) syscall man page:
     There are ways for a root process to escape from the chroot jail.
     Changes to the directory hierarchy made from outside the chroot jail may
     allow a restricted process to escape, even if it is unprivileged.
     Passing directory file descriptors via recvmsg(2) from outside the chroot
     jail may also allow a process to escape.
