It'd be a relatively narrow window - it didn't affect RHEL 5/6/7 or the Ubuntu releases, so it'd need to be someone running a recent enough kernel to catch it but unmaintained enough to not push out the fixes.
Presuming this landed in 4.8 (guessing based on the kernels Debian listed fixes for versus not affected [1]), which came out in October 2016, that's 2 months of time when someone could have picked a stable release and gotten bitten by this.
update: it's actually even narrower, since it looks like those lines were added in a patch from November 3rd [2], so maybe a month.
[1] - https://security-tracker.debian.org/tracker/CVE-2016-9919
[2] - https://www.spinics.net/lists/netdev/msg402791.html