If distro maintainers are going to futz with packages, for good reasons or bad, then they need to bear the corresponding support burden themselves and ensure it does not fall on the upstream maintainers. This is not really any different from the Debian OpenSSL fiasco, or the Debian cdrecord fiasco, or the Debian xscreensaver fiasco, or...
says it was hardly a Debian thing. More to the point, I'd argue that there is a meaningful difference between "we're going to patch this" and "we aren't confident that we can ship this at all".