Nobody else has this hybrid model. RHEL is a paid distro in general. Most others are just free entirely. They all patch CVEs when they can. Ubuntu doesn’t write all of their patches or anything.
If you are running things inside of containers you aren’t helping yourself by disabling unprivileged namespaces, you are actually just running more things as root. Inside the containers they generally block namespaces anyway.
TBH I’ve never heard anything positive about most of what hardened does.