Prove it.
Prove it.
As I've said script kiddies probably fail at exploiting this but if you have valuable infrastructure to maintain and you've got someone talented or bored on the other side or even inside your network i.e. university networks where you can't reboot everything every other day it's not unrealistic.
First up, nearly half of this years priv esc bugs in Linux so far are specific to Android (and most of those involve things like nvidia drivers). That's serious, but not "somebody can get root on my server" serious.
Another handful of them are specific to some driver, some kernel module, or some kernel feature, that would only be used on a subset of systems. Still bad, but it does mean that at any given time, even systems running theoretically exploitable systems often won't be because the feature needed to exploit it isn't turned on and can only be turned on by root. For example, one of the high scoring vulnerabilities requires a user or process with CAP_NET_RAW capability. That has to be granted by root, and would presumably only be granted to trusted users and processes.
But, others are pretty scary and would be exploitable in a lot of cases. It's a reminder to stay on top of updates. And, also a reminder that the kernel is a huge surface area for attacks. It sometimes seems like a miracle that any of this stuff works at all.