Vždyť si zase vymýšlíte. V případě Linuxu kernelový tým o zveřejnění vulnerability jedná s objevitelem a autory distribucí: A disclosure date is negotiated by the security team working with the bug submitter as well as vendors. Takže jsou veřejné přístupné informace jen u těch vulnerabilities, u kterých v daném čase nebylo dohodnuto s objevitelem zranitelnosti odložení zveřejnění.
https://www.kernel.org/doc/html/latest/admin-guide/security-bugs.html
Tak si to alespoň přečti...
The goal of the Linux kernel security team is to work with the bug submitter to bug resolution as well as disclosure. We prefer to fully disclose the bug
as soon as possible. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested or for vendor coordination.
However, we expect these delays to be short, measurable in days, not weeks or months. A disclosure date is negotiated by the security team working with the bug submitter as well as vendors. However, the kernel security team holds the final say when setting a disclosure date. The timeframe for disclosure is from
immediate (esp. if it’s already publicly known) to a
few weeks. As a basic default policy, we expect report date to disclosure date to be on the order of
7 days.
Takže žádných
běžných 90 dní, který kolikrát MS na opravu ani nestačí.
A mimochodem, on neřekl, že jsou informace dostupný hned, jen to, že se zvěřejní.