It's not a stance I agree with but I think their logic is something along the lines of: anyone shipping GPL code who patches a security vulnerability must also make available the code for that patch. Compare that to a BSD license for example where two companies may be running the same software but one has access to patches the other does not.

