In a similar vein:
Raising alarms on a CVE in Apache2 that only affects Windows when the server is Linux.
Or CVEs related to Bluetooth in cloud instances.
Or raising alarm on a CVE in linux mlx5 driver on an embedded device that doesn't have a pcie interface
Or raising alarm on a CVE in linux mlx5 driver on an embedded device that doesn't have a pcie interface