when multiple independent parties are simultaneously tripping over different holes in the same kernel, that's not bad luck, that's a systemic attack surface problem
Large majority of CVEs in the update are related to memory corruption, out of bounds and use after free.
Naturally the logic and wrong permissions ones would happen regardless of the language.
https://en.wikipedia.org/wiki/Capability_Hardware_Enhanced_R...