I would think a) this are mostly system tools like boot managers and b) these tools need root (or setuid root) anyway, so why can't they just mount it themselves temporarily?
Edit: It seems it is mostly grub-install, efibootmgr, and `systemctl reboot --firmware` that need this mounted rw. The first two aren't something that a casual user uses very often, and if someone does, a "Filesystem is mounted read-only" message will point them in the right direction. The latter is part of systemd and could easily be changed to mount efivarfs itself, no third party involved.
It does not change the fact the fault lies with shitty proprietary UEFI implementations, and nobody writing free software is at fault here.
The kernel fix prevents that, using mount flags alone only restrict the vulnerability but it doesn't make it go away.