
2 days
i’m pretty sure the kernel itself does that to themselves too. basically there’s so much code in the kernel that if any bug, even if small, could possibly under a specific configuration result in some device out there having its security weakened, they prefer to be on the safe side and assign a cve.

the dependencies? all distros have those, unless everything is statically compiled (bad idea) or you could potentially have less of them if you run gentoo and unset a lot of USE flags.