> What if xz contains a hidden buffer overflow or other vulnerability, that can be exploited by the xz file it's decompressing?
If you generalize this problem further, to all packages, then the only reliable solution is security through compartmentalization. On Qubes OS, any file I open, including .jpg and .avi, can't have the access to my private data or attack the admin account for the whole computer. This is ensured by hardware-assisted virtualization.