Apologies as I have not read all 11 pages of the thread, I'm only here to add and not investigate so wasn't going to punish myself.
We were not going to resize RE partitions of our server estate so when this update and issue came out I logged a call with MS Support, this is the fix they provided and (to date) it has worked on all affected servers:
As scoped issue, we got to know that you are getting WinRE partition on deployed devices to address security vulnerabilities.
but this update is particularly meant to the server which have WinRE partition.
a. If the System just don’t have Recovery partition but WinRE is still enabled on OS, it should not prevent the device from receiving the updates for WinRE.
i. Instead, the WinRE servicing should succeed without any additional steps since we have more space to use on OS
b. If the System is having a Recovery partition but WinRE is disabled, you need to try run “reagentc /enable” to enable the WinRE onto the Recovery partition.
i. If the enable failed as Recovery partition is not big enough, you will need to extent the Recovery partition.
c. If the System didn’t have a Recovery partition and WinRE is disabled (as cannot be install onto OS partition due to BitLocker), you need to manually create a Recovery partition first.
Else :
1. Ignore installation errors on devices that do not have WINRE partitions.
2. or fallow the below AP to bypass the updates:
Action Plan: