So a Linux/Windows kernel crash triggered by a normal user would get a CVE. Why doesn't this get a CVE? Especially as it's fixable with a microcode update...
I think we need to cover hardware cases where it bricks/crashes the system/hardware at a minimum.
Also I always thought AMD was a CNA, but they're not?
--