The original maintainer of #xz (Lasse) just fixed another affected piece of code that sabotaged library sandboxing and was, of course, also introduced by the malicious contributor Jia Tan.
https://git.tukaani.org/?p=xz.git;a=summary
This poor unpaid Fossdev probably has a ton of companies knocking on his door right now.