Is a dangerous version of xz being used?

Version 5.6.0 and 5.6.1 of xz included some backdoor code to ?? open up SSH to unauthorized access in the right circumstances ??.
Do any of the RTEMS installers pull these versions, or does the tools build just use the host’s install of xz as it is?

The RSB uses the host OS provided xz. There is no configuration file or build set file in the RSB to build xz.

We recommend you keep your host operating system upgraded.