No matter how you mask off attack surface for the kernel, you're not super likely to want to disable io_uring, is the point I'm making. It's easy to find recent threads here with people sticking up for shared-kernel multitenant isolation.
(Be forewarned that I'm talking my book a bit here, since we have a commercial thingy built on multitenant VMM isolation).