Desktop Linux in general seem to have a very large amount of probable vulnerabilities, but it also has a very large community of companies that sponsor work and rely on it for servers.
Would be interesting to see how quickly an open back-door is fixed after it's discovered. Is the maintainer available? If not, can the package be replaced? Will it be vulnerable for months, years? So many uncertainties make me not want to rely on Desktop Linux for sensitive work.
from my past experience, faster than on windows or mac. the application maintainers need not be available. the distribution maintainers can step in and apply fixes to the versions they distribute.
if a 3rd party windows application has a security issue, good luck getting any fixes.
Would be interesting to see how quickly an open back-door is fixed after it's discovered. Is the maintainer available? If not, can the package be replaced? Will it be vulnerable for months, years? So many uncertainties make me not want to rely on Desktop Linux for sensitive work.