Containers share kernels between tenants; that's the point of the design. The shared kernel is a huge security problem; it's easy to rattle off kernel LPEs that no realistic syscall filter would have prevented and that would pop a container runtime.
It is not similarly easy to do that with a lightweight hypervisor.