It needed to be "fixed" but not necessarily on anyone's time table besides the ffmepg volunteers, or alternatively given it is an issue with specific coded and not the core of the encoder or something, it is up to people that build and ship ffmpeg with they projects to disable that codec and rebuild and push an update.
If Google is paying or providing support infrastructure, hosting, etc they don't get a say in feature / fix priority. Just because 'security' gets added to the strings that constitute a bug report in a FOSS application should not suddenly mean that it becomes the most critical task, nor should it place some obligation on the authors to provide a fix at all.
The FOSS projects really need to learn to respond with "Look this is a hobby, and as a craftsman I take pride in my work, and i am trying to write clean, secure, correct code. However my priorities features and fixes that I care most about and other contributors sending high quality pulls care about, and those might not be yours, even if you think it they impact security. If you want determine how we spend our time directly, many of us are willing accept contract work."
FOSS projects need to reject this notion that just because a cabal of mostly commercial ISVs slap a CVE on something, they owe the world a patch even if it means losing sleep or skipping their camping trip to work on hobby they did not plan to make time for that month or three!