Yeah no, the same was said about the previous vulnerability in the SSH server. News stories just assume when people run an unpatched version they are vulnerable from attacks from the internet and run with those numbers. It makes for a better story, but it isn't the whole truth. OOTB these kinds of things aren't exposed to the outside world and exposing them isn't trivial.
People should still patch and these vulnerabilities aren't a good thing obviously, but the news stories have been pretty sensational for something that probably won't impact a lot of users.