The latest (yes another) Linux kernel LPE also relies on an exotic socket type, AF_NETLINK. If you lock down allowed socket types to just internet+unix, you are safe.
Unfortunately even rootless podman relies on AF_NETLINK sockets via pasta (user mode networking), so it's trickier if you're using containers. Good time to reconsider if you really need all the extra complexity containers bring.