You'd want the delay between first publication of X and the microcode update making its way into releases of OSes to be smallest, for various values of X (mention of a vulnerability, microcode patch, description of vulnerability, PoC). Making various OS releasers aware that a microcode patch that fixes a vulnerability will be published on a given date before that date decreases that for most values of X.
Won't that theoretically allow malicious actors to study the patch and exploit the now 1-day vulnerability?
Not that I think it's realistic to develop an exploit and gain real value in three days, but theoretically, if all parties had taken more than three days to distribute and apply the patches?
> As the fix is now public, we propose privately notifying major distributions that they should begin preparing updated firmware packages.
AMD had to drop the ball somewhere didn't it.