It wasn't the Linux kernel developers who filed for the CVE entries. They never do. How do I know? I reported a vuln once (an LPE if I recall correctly).
Someone wants to pad their resume so they can get a job in the security field.
And you know what, if they're making open source software more se...