Yes, and you should be on the CU train anyway in my opinion.
The GDR train means that you take the RTM version with all its bugs etc, and stay on it, applying only GDRs (which is basically only security fixes).
If you take the CU train, you will also get GDRs if they are released between two CUs (and that happens). I believe that they also release GDRs for a few CUs back, but not all.
If we take SQL 2017 as an example the current CU is CU22 (if I recall correctly). Say that a security is found. They will release a GDR for CU22, and maybe also CU21, CU20 a few more (I don't know the exact policy here). They will also release a GDR for the RTM version without any CU.