It looks like their open source disclosure of the kernel source is a 4.4 kernel, so something weird is going on there. Maybe they got off 2.6 since the time the vulnerability was discovered?
I see something saying they moved to 4.4 in the 8.1 update in June 2017, which is confusing because it suggests the vulnerability was never live.
But I also see they have multiple CPUs running Linux and don't update the kernel on all of them at the same time, so perhaps the CPU running the 8686 driver wasn't updated?