The number of places that are still potentially vulnerable to weak shared memory permissions...

https://codesearch.debian.net/search?q=shm.*\(.*[0-9][0-9][67]&literal=0

Debian Code Search: shm

Worth noting that after that paper's release I did further work and found examples that would yield code execution and LPE.