Fix packages for CVEs

Hi,

Unsure where to post it so please move if need be
Regarding fix packages for CVEs - the architecture specific ones - are they provided on a case-by-case basis?
Meaning, if a CVE is only relevant to aarch64 for example, would SUSE provide packages for all architecture regardless, or would the release comprise of aarch64 packages only?