That's definitely not what he did though. He did research on the internet, going through various websites and articles listing options, and asked ChatGPT. That's imo more than what the average user does (or is even willing to do).
He then picked the distro that he saw was being recommended most to him. He installed it with default options, which ended up being Cosmic. Which is improving fast these days, but it's still a bit unstable. But the install process won't tell you that.
Pretending that these users are "bad users" or that highlighting these issues that regular users run into is disingenuous or somehow irresponsible is just unfairly dismissing a valid perspective.
The whole "Linux just works"-shtick just isn't always true. And the sooner the community learns to accept that and works to help these users with their issues, rather than stomping their foot angrily whenever someone shows up highlighting problems. I'm pretty experienced myself with a job in software development, but even I needed to reinstall Bazzite 2 times when installing it for my sister because I somehow messed up something when mounting the hard drives, getting Bazzite stuck in an unrecoverable bootloop (none of the recovery options suggested online worked either). I hate Windows as much as the next guy, but I've never been able to manage that on a Windows install (once running Bazzite ran fine btw, just the setup was frustrating).





Erm, did you read them? The policies aren't complex at all, just submit the issue (and proposed fix if there is one) through a secure channel, that they're happy to help set up. If you want to disclose the vulnerability, just wait until the embargo passes so there's time to fix and have users update. There's not really anything else you need to do here. This is pretty standard stuff that this person just seemed too lazy to participate in.
Of the three fixes submitted, only a single one was closed since it didn't seem very major and would be a breaking change (which shouldn't be made without prior discussion). The other two are still open, and a maintainer is helping to add tests for the fixes (since the author didn't add them). The only comment that was somewhat negative was that security fixes should preferably follow the established guidelines. That's all.