Pretty much any kernel bug gets a CVE by default now, right?
yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln
one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.
Yes. It looks funny, but it's a nothing burger.
Is that all there is here? The quantifier "several" did not prepare me for the wall of CVE numbers in this list.