The tool https://gitlab.com/divested-mobile/cve_checker is fascinating; I've usually seen people attempting to bring needed drivers to a mainline kernel, but backporting security fixes to a vendor kernel does seem like a plausible way to get a lot of the benefit with less work.