What I would have done differently:
1/ report the Google Fuzz Report to the actual development team, to coordinate and collaborate on a solution.
2/ not take three whacks at a security release just to fix the same vulnerability
3/ not attempt to ship whimsical patches in a security release
4/ not patch the test suite to lie to voters about the viability of a release candidate.
5/ ship a hotfix immediately after users report the bugs on 2.17