They aren't exactly linux firewalls, even if they run linux as management OS.
AFAIK the forwarding engine is custom(ized), and on physical devices some of them offload to FPGA - or at least they used to when I administrated some 2014~2016.
They probably mean some Linux distro with no crapware on top. Seeing how this exploit seems to be PaltoAlto-specific stuff built on top of the basic OS, GP's approach sounds sensible enough.