Depends on the impact? CVE scores are known to be a worthless metric when looking at the actual impact.

Linux now labels every single bug as a CVE.

I think they mean what is the actual vulnerability and not the score.