Hey. There's even an allegedly "wontfix" bug of mine where I requested that Debian switches back to a secure default and disables user namesapce which have a long history of being exploitable: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1012547
Don't think the current hole one will have been the last one. Unfortunately it seems a feature that only a group of people will need is valued more important than keeping users secure. :-( Regards, Philippe