I would hope that enterprise Linux vendors would be willing to pay for details of Linux vulnerabilities, as their customers are security conscious and these vendors already invest a lot in security. For those vendors that use a close to mainline kernel, this would also help the wider Linux community.