abadidea (@0xabad1dea@infosec.exchange)
so after blearily reading a bunch of blog posts immediately before bed I have come to the conclusion that only one month between the commits and Andres Freund sending what I hope is the most dramatic mailing list post of their career is actually a pretty good turnaround, this could have easily...

Basically someone successfully inserted a backdoor into an upstream tarball for a library ssh relies on and thus compromising any server using Linux. It was discovered thanks to performance regressions and some valgrind errors on some systems.
Luckily xz 5.6.0 and 5.6.1 have not yet widely been integrated by linux
distributions, and where they have, mostly in pre-release versions.