Say my enterprise application is built upon the API (in an abstract sense, if you will) of package xyz, version 1.0. And then xyz, version 2.0 comes out.
I would have to rebuild my enterprise application to be compatible with API 2 and I don't have the resources nor the incentive for that because I don't need API 2. Then a vulnerability gets reported in both xyz version 1.0 and 2.0 but xyz's maintainers only patch 2.0 (as 2.0.1).
In that case I am very happy that non-rolling (enterprisey) distro's like Ubuntu, CentOS, Redhat etc backport that security patch so I can keep running xyz version 1 (or rather 1.0.0-1 or something like that). Where most rolling distro's would just 'force' you to upgrade to 2.0.1.
Hope my explanation makes sense.