In case anyone wonders if the #Linux CVE team releases #LinuxKernel CVEs before the problem is fixed in stable and longterm series:
Yes, they sometimes do this when the fix hit the mainline #kernel; not that often from a quick look, but yesterday I noticed two such cases by chance:
https://lore.kernel.org/all/2024040122-CVE-2024-26653-7903@gregkh/
https://lore.kernel.org/all/2024040142-CVE-2024-26654-aa6c@gregkh/