-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
those people might run self-compiled versions of Tor that are more up to date than they seem from the version string.
Alternatively, some of those relay operators (independent of the version that is shown in the descriptor) might run a version provided by their packaging system that backports security-relevant issues but leaves the rest of the updates alone, and thus doesn't increase the version.
This is also interesting in the context of #2980, #2988 (Not reporting version is actively harmful).