>From https://wiki.yoctoproject.org/wiki/Stable_branch_maintenance:
General policies:

  *   Fixes must go into master first unless they are applicable only to the 
stable branch; if back-porting to an older stable branch, the fix should first 
be applied to the newer stable branches before being back-ported to the older 
Does anyone know the reason for the policy above i.e. why fixes have to go to 
master first?

1)      It makes more sense at least for users  to get CVE fixes as soon as 
possible in the maintenance branches.

2)      Normally the versions are different in master and maintenance branches 
so different patches are required.
