The only possible course of action is to hold the root responsible and to remove them from the trust store.
The CA system is fragile enough as it is and only the prospects of immediately going out of business can be any deterrent for CAs not to start doing shady stuff.
Yes. Revoking the root is annoying for customers of that root, but I'm sure other CAs will gladly offer a free or really cheap replacement program. And if the affected root is REALLY big, then just pre-announce the revocation for a year or two. Just like what Google is doing with the sha1 certs.