Honestly this is probably me going off of outdated or even incorrect information. The fact that it has little adoption for that use case or as a root filesystem is probably the larger factor.
It’s been awesome to see Ubuntu embrace it over the last few releases though and that’s certainly starting to change things but since it’s not part of the Linux kernel that gives most other distros pause I think.
TLDR: Ubuntu Pro offers additional security patches to packages found in the universe repo. Universe is community maintained so Ubuntu is essentially stepping in to provide critical CVE patches to some popular software in this repo that the community has not addressed.
I suppose it depends on how you look at it but I don’t really see this as withholding patches. Software in this repo would otherwise be missing these patches and it’s a ton of work for Ubuntu to provide these patches themselves.
Now is they move glibc to universe and tell me to subscribe to get updates I’ll feel differently.