I think that the draft should point out that a sender MUST NOT send non-KEX messages after he _sent_ a KEXINIT message. he has to delay all non-KEX messages until he has sent the NEWKEYS message.