I heard from a friend who knows someone in Crowdstrike that this bug had been sitting there in the kernel driver for years before being hit. Turns out that the flawed data was added in a post-processing step of the configuration update, which is after it's been tested internally but before it's copied to their update servers.
Their test setup was fine for the update data itself, it's just that they didn't catch it before it was sent out to production because they were testing the wrong thing. Oops.