Because my airplane was delayed, I played with kernel CVE data, and summarized[1] the buggy and error-full results.
TL; DR: About 95% of CVEs that affect the mainline tree has fixed before those are reported by linux_kernel_cves project. The number was 76%, 69%, 73%, 78%, 83% and 82% for 6.4.y, 6.1.y, 5.15.y, 5.10.y, 5.4.y, 4.19.y, and 4.14.y, respectively.
The worst case time between linux_kernel_cves report and fix commit being fixed was [16, 32) weeks for the mainline. For the stable trees, the number was [4, 8) weeks (6.4.y), [16, 32) weeks (6.1.y and 5.15.y), [32, 64) weeks (5.10.y), [64, 128) weeks for 5.4.y, [32, 64) weeks (4.19.y and 4.14.y).
[1]
https://github.com/sjp38/lazybox/blob/master/cve_stat/report/report.md#linux #kernel #cve #stable #lts