I will grant you "simple", and maybe even "common"... but only because most people don't really understand decentralization and many of the ones who do don't care about it.
The "actual" way this happens, for the protocols and contracts that "actually matter" (certainly almost everything you would have heard of, as opposed to the long tail of tiny pet projects) is that, in the case that a bug is found, all of the users have to vote with their feet to move to and accept a new one.
Essentially, this is equivalent to saying "decentralized contracts simply aren't upgradable", but of course everything is upgradable if you accept the idea of people giving up on old software and using new software ;P.
(If this sounds familiar, it should be: this is in a very real sense similar to how Wireguard intends to deal with cryptographic breaks in its chosen cipher suite, as they aren't some centralized power able to upgrade everyone's computers remotely.)
(FWIW, there is something else you can do, but as it would be implemented by still more contracts that themselves might have bugs I don't consider it the answer here as it begs the question: you make a contract--hopefully a simpler one that is less likely to have a bug--that lets people vote on which contract is the current accepted one, assuming they can all have compatible APIs.)