Earlier quoted context omitted.
> Red Hat still has to release the patches, right? I think that's a gray area. For example RHEL has some support branches where they'll produce security updates for minor updates. For example you can pay a lot of money and you'll get RHEL 7.2 with security updates. They won't release sources for those packages unless you'll ask for those packages (you, as a paid client, not you as nobody in the Internet). But if you'…
> They won't release sources for those packages unless you'll ask for those packages (you, as a paid client, not you as nobody in the Internet). If the code in question is licensed under the GPL and Red Hat isn't the owner of the code, then I as a rando on the Internet can ask them for the source and if they don't provide it, the person who does own the code can sue them and revoke their license to distribute said co…
This is why the cloud providers can get away with custom in-house patches to the Linux kernel.