Very well. Here -
https://www.debian.org/security/2008/dsa-1571
https://www.finnie.org/2024/05/13/i-discovered-the-debian-openssl-bug/
That's the thing about "pure human slop": it doesn't need to be malicious to be catastrophic.
The second link is particularly salient - kills the "supply chain attacks are special" argument because it is precisely about "unwitting bugs in normal human-written code just happen"