I am afraid the dataset is too limited to be useful.
What would be informative is to take an old kernel (says 2.6.18) and to
look at the report date of all reported vulnerabilities that affect it.
This way we would know how much time it takes to find vulnerabilities.