I don't think you should trust the recruiter's VM any more than their code. Spin up instead your own disposable VM or container with no creds or host mounts.
Clearly, judging by recent openai news, sandboxes are not unbreakable, but at least there's nothing worth stealing and you throw it away afterward.
On a headless VM, almost certainly it's not a worry, since that bug needs a physical port and the driver binding to a plugged-in device (so basically it's never reached). You could even prove it running lsmod showing the module is not loaded (so "not applicable"). Unfortunately the CVSS score doesn't carry reachability information, and not just for the kernel CVEs.