what's terrible with Linux that so many software has libraries compiled into the binary.
This means that every single software that has shit compiled in has to get updated too, which is plain retarded.
See for example the Google webp / webm garbage formats. So many security issues (probably intentional), and so many software has libwebp compiled in. Some browsers like even Brave do not even allow you to disable these garbage formats, all you can do is modify headers to not ask for these formats in the first place.