They share the host kernel, and this architectural reality creates escape opportunities that do not exist with hardware virtualization.