Anyone running an older kernel with SCTP reachable should update. The flaw is local, not remote, and it needs SCTP reachable on the target, which limits exposure. Per the kernel's own advisory, one message can carry an address, a delete for that same address, then a wildcard delete. Vendors often backport fixes without moving to a new upstream version, so a kernel version string alone will not tell you whether you are covered; check your distribution's tracker. It also lands the same day as Zapscape, an unrelated KVM escape, and the same four stable releases carry both fixes.