"If you're not using the latest kernel.org kernel, you're only getting a fraction of the vulnerability fixes that should be backported."
It would be nice to have this statement either validated, or refuted. Which vendors are vulnerable because they have not backported a vulnerability fix, because it isn't disclosed as such in the commit log? It must be many if only "a fraction" of such commits are backported.