Add option -nn so that the Device ID is shown too. We usually seek/check with the ID.
The kernel and its modules can be signed. The unsigned cannot load, if the Secure Boot is enabled in EFI.
The kernel-ml is not signed. You could not boot it at all with Secure Boot is enabled.
Look at dnf list kernel\*. Aren’t there ‘-modules-extras’ in addition to '-modules’?
Not sure whether the extras actually help, but if they are not installed now …