I agree with that. A company that earns money from its Linux distribution should be quicker to fix a vulnerability of this kind. This particular vulnerability has received quite a lot of public attention, and it is also one of the first to have been discovered with the help of AI.
Rocky Linux is closely tied to RHEL through its bug-for-bug compatibility approach, whereas Alpine Linux is free to react more quickly and independently. That said, Rocky Linux is apparently considering alternative approaches for handling urgent security bugs, which I think is a positive development (see https://forums.rockylinux.org/t/rocky-linux-needs-your-input-regarding-urgent-security-updates/20389)