Is this so? Can this kernel panic also be triggered in TCP connections initiated by the victim? I can't find a conclusive mention of this anywhere.
As each direction of a TCP connection has its own MSS, it would make sense that an attacker's server could exploit this.