Although no Debian stable versions are known to be affected by CVE-2024-3094 the next point release for 12.6 has been postponed while we investigate the effects of this CVE on the Archive. https://lists.debian.org/debian-security-announce/2024/msg00057.html
Good question. Maybe it has to do with the fact that the backdoor contributor was on the xz project for about two years.
Yep. All distros are rolling-back to before JiaT75 was involved.