Since Lineage OS is a fork of the Android Open source project (AOSP). All security commits that are added to AOSP eventually end up in Lineage OS. Say for example, there was a vulnerability that was patched and it was added to the AOSP source code. It ends up going to the Lineage OS code and the team that handles the core of LOS might tweak it to have it work better with it's codebase. Then it gets turned into a device specific image and you get updates.
I had a moto e2 lte that lost support right after I got it in early 2016. (I live in the US, US, Aus, and CN markets stopped getting updates after Android 5.1.1 while everywhere else for Android 6). With Lineage OS I'd still get updates.
That being said it's been a decent while since I've worked with Lineage OS as that phone struggles with anything past android 7. My information isn't the most accurate but it's the general gist of it.