Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
(www.theregister.com)
It kinda depends, on custom kernels DKMS can be incredibly helpful. Like for a hardened kernel, a lot of drivers may be loaded via DKMS.