If kernel developers don't know this, then how on earth are regular folks supposed to know? (rhetorical)
Just excuses, IMHO. If something is _known_ to have security implications, then it should be called a security fix. The rest of the stuff, of course, _may_ have security implications too, but they are not yet known.
Every other software on the planet uses this convention, but Linux developers decided to obfuscate. Ah, well...