Even KVM escapes have been demonstrated. KVM is not a security boundary ... except that in practice it is (a quite effective one at that).
Taken to the extreme you end up with something like "network connected physical machines aren't a security boundary" which is just silly.
1. This is why some places with secret enough info keep things airgapped.
2. OTOH, from what I recall hearing the machines successfully targeted by Stuxnet were airgapped.
In our threat model the upper bound on the useful lifetime of the system is limited by the light-distance time from the nearest adversary.
What percentage of malware is programmed to exploit Docker CVEs vs. just scanning $HOME for something juicy? Swiss cheese model comes to mind.