RIOT should have a defined policy on how to handle security released bugs. After a small survey of other OSes, this seems to fit best with RIOT.