@AffSeda It doesn't work like that. Something like that could happen with any library - it's not the reason for starting a witch hunt. Backdoor is detected and patched. End of the story.
But you are right - it HAS to be checked.
Hello @AffSeda, in general, Steam uses the host system libraries or libraries from Steam Linux Runtime.
You can review the libraries used in the various Steam Linux Runtime container environments at https://repo.steampowered.com/.
In particular, Steam Linux Runtime - Scout (https://repo.steampowered.com/steamrt-images-scout/snapshots/latest-steam-client-general-availability/sources/) has xz-utils_5.1.1alpha+20110809-3 and Steam Linux Runtime - Sniper (https://repo.steampowered.com/steamrt-images-sniper/snapshots/latest-container-runtime-depot/sources/) has xz-utils_5.2.5-2.1~deb11u1.
This summary predates the CVE in question.
Nothing extracted yet.
Your system information
Please describe your issue in as much detail as possible:
It's possible the current xz-utils package is, was, and always will be potentially malicious. Is it possible that the Steam client can be reworked to not require this package?