The CVE tracking pages are here:
https://access.redhat.com/security/cve/CVE-2023-0590
https://access.redhat.com/security/cve/CVE-2023-1249
https://access.redhat.com/security/cve/CVE-2023-1252
Based on these data, it seems that the commercially supported versions are still unfixed (if they were impacted in the first place).
Bugzilla records show that the corresponding security tracking bugs were filed publicly from the start:
https://bugzilla.redhat.com/show_bug.cgi?id=2165741 (CVE-2023-0590)
https://bugzilla.redhat.com/show_bug.cgi?id=2169719 (CVE-2023-1249)
https://bugzilla.redhat.com/show_bug.cgi?id=2176140 (CVE-2023-1252)
So the Neowin headline is a bit misleading because Red Hat disclosed these issues publicly (presumably after consultation with the reporters) even before the 90-day timer expired in the Google bug tracker.
(Disclaimer: I work for Red Hat, but are not involved in security anymore.)