We shouldn’t wait for the rebuild, xz
, libarchive
, all related packages should be removed/marked insecure and pushed to master.
Let people rebuild what they need themselves.
There is reason to believe that older versions are possibly compromised too.