Is all audit work related to advisories?
Actually no. There are many security issues that the audit process has found that are not immediately exploitable (they might, however, make a program crash). Some other exploitable security issues we’ve found were not present in Debian’s official stable release but were present in the testing or unstable release. All of these are reported through Debian’s bug tracking system (and in some cases directly to upstream authors).