How is that “a problem with FIPS?”
In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later.
You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.
If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.