Container escape
An escape crosses from the workload out to the host, which means every other container on that host.
It usually requires either a kernel flaw or a container that was given more privilege than it needed. The second is far more common, and it is a configuration choice rather than an exploit, which is why hardening pod configuration does more here than patching alone.
Checked against the primary source.
