Thanks for your answers. I was just taking these 2 flaws as examples to understand the workflow in such cases. Still interesting to know that these 2 are not affecting us too much.
So if I correctly understood patching the kernel would be responsibility of the port maintainer(s).
