This skews the CVE stats significantly since the kernel developers (aka kvm) rarely actually request CVE ids.