Is there anything to stop RedHat from pulling patches from Rocky? Is Rocky's code not available? Rocky isn't doing anything that CentOS (and RedHat project) isn't as far as I know.
The problem isn't Red Hat getting them, the problem is a Rocky "customer" would have to just wait for Red Hat to release the patch and then wait for rocky to re-build, and re release.