@feld @Bredroll
He allegedly got the 9.9 from somebody at Red Hat.
However, despite being the one who was intimately familiar with the vulnerabilities, he didn't bother to check the scoring himself. (It's not terribly tricky)
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Instead, he chose to amplify the wrong information and kick start the rumor mill process. Because more fame is better than less fame, apparently. 🤦♂️