On Linux, the attack surface may not be non-existent, but by default it is smaller than some other operating systems. Any halfway competent Linux sysadmin can configure iptables or some other firewall to block all network traffic except what is specifically permitted. Even when something is exposed, it usually only allows access to specific user accounts (including system service accounts.) Once access is granted to an account, you are then constrained by discretionary access controls (DAC) (i.e. POSIX users + groups + file permission modes), and, for the paranoid, by mandatory access control (MAC) (eg AppArmor or SELinux) as well.
As others have said, such access could theoretically allow bootstrapping to greater privilege escalation, especially if you only have DAC and no MAC, but in practice it's harder than it sounds.
I have seen plenty of publicly-exposed Linux VMs compromized over the years. They were always compromized via one of two methods: the admin user explicitly enabled password authentication to ssh instead of adhering to keypairs (which we enforce by default); or, they opened up a vulnerable service such as a database to the public internet. It was never via some virus.
You hear people saying dumb stuff like, oh no one uses Linux and that's why there are no viruses. To that, I say our Linux server farms have a vast amount of highly valuable compute power and research data. If it were possible to infect these machines with a virus, any halfway competent nation state, ransomware group or bitcoin mining conglomerate would very much consider it a worthwhile investment to develop such a virus.