Clearly I was too subtle. It, uh, wasn't actually a hypothetical: zlib had known exploits that bit Microsoft and others for years because they had cut and pasted the library into a zillion places. Linux distros just updated.
There's no theory at work here. Static linkage of common components is a security vulnerability.
There's no theory at work here. Static linkage of common components is a security vulnerability.