For this particular example, wouldn't this be best solved with a separate runlevel for "reboot into UEFI"? Stop all daemons, remount all normal filesystems read-only, remount UEFI RW, write variable and reboot.
The kernel fix prevents that, using mount flags alone only restrict the vulnerability but it doesn't make it go away.