Since no one got around to answering this through all the flamewars: the initial detection was loading the vulnerability via libsystemd (used for sd_notify)...