The xz backdoor was caused by packagers patching OpenSSH. Just because it was caught you don't get to pretend it doesn't count.
How many people double check that apt actually updated the package to the right version, if it’s output is compromised?
Which library pulled the vulnerability in is mostly irrelevant.
And that was what happened with systemd.
But no. Newer versions of systemd have issues, and this was what systemd pushed. Just why do you think all these distros had the sane patch? For fun?
Arch would have ended up with it eventually. It wasn't Arch being prescient, Arch wasn't using the same systend version as Debian Unstable, and other distros bleeding edge branches.