(EDIT: as others have pointed out, part of the exploit is in the artifact from libxz, which Arch is now avoiding by switching to building from a git checkout)
I've never had to do it myself but I believe that's common practice with embargos on security vulnerabilities.
Also, https://mastodon.social/@mgorny@treehouse.systems/1121802382... from a Gentoo dev mentions that Gentoo doesn't use the patch that results in sshd getting linked against liblzma.
As far as I know this is not an official communication channel so don't take it as such.
But with pacman/makepkg 6.1 (which recently released) git sources can also now be check summed IIRC which is a funny coincidence.
[root@archlinux ~]# pacman -Qi xz | head -n2
Name : xz
Version : 5.6.1-2
[root@archlinux ~]# pacman -Qi openssh | head -n2
Name : openssh
Version : 9.7p1-1
[root@archlinux ~]# ldd $(which sshd) | grep liblzma
[root@archlinux ~]#
It seems that Arch Linux is not affected.I agree on the sshd linking part.
https://archlinux.org/news/the-xz-package-has-been-backdoore...
Note that I'm not looking for the vulnerable symbols, I'm looking for the library that does the patching in the first place.