I have been responding directly to Howell's ticket regarding this issue, but he doesn't like my answers.
What Howell is not understanding is that we do not have the flexibility to make critical security fixes opt-in.
When the FBI or other organizations contact us about critical CVEs, we must explain exactly how we resolved them. This means the issue must be resolved when a customer updates, not at the customer's convenience.
If we tell them that a fix would inconvenience us or our customers, that simply doesn't fly. They expect critical security issues to be resolved immediately and without requiring additional action from the customer beyond updating the software.
It is our recommendation that you update your server immediately to protect both your server and your users. If you choose not to update, that is your choice. We are doing what we are obligated to do to address the security issue.
This topic and discussion are now closed.