The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.
The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.