"As a perhaps amusing aside, if everyone were to follow our suggested delay practice, it would become much less effective. Fortunately, we have no expectation that everyone will listen to us."
Unpopular opinion: more people should follow this advice.
Unfortunately, many feel they have no choice but to deploy patches with a "security fix" label on them more quickly than they normally would make changes to complex systems.
#CVE #InfoSec
https://shostack.org/files/papers/time-to-patch-usenix-lisa02.pdf