Isn't biggest attack surface in drivers?
That would be my guess too, the current batch however is all over the place: Bluetooth, file systems, etc. (the network layer ones are probably the most interesting ones). And the severity is mixed as well, some are 'just' vulnerabilities to potential DOS attacks.
I expect distros to split less popular kernel modules into many separate opt-in packages
In the past questionable modules were blacklisted rather than removed.