3 ms·
Isolation. uid 0 is treated specially, and root breakouts inside containers (especially containers which aren't constrained by the audit subsystem in some way,
by evol262 11y ago
Isolation. uid 0 is treated specially, and root breakouts inside containers (especially containers which aren't constrained by the audit subsystem in some way, like grsec or selinux or apparmor) or kernel exploits can bust your whole system open, among other security risks with containers.
hypervisor breakouts exist, but they're much rarer.