A short time ago a "local root" exploit was posted to the full-disclosure mailing list;
You don't know what you're talking about. This exploit appears to give local users root privileges, making it a local root exploit exactly as the security advisory states.
The phrase "localhost vulnerability" remains meaningless techno-babble. Localhost refers to a network address and this exploit appears to have nothing to do with that.