The vulnerable unexpand(1) code path (multibyte -t handling) was
introduced upstream in GNU coreutils 9.11. Debian trixie ships
coreutils 9.7-3, which predates it, so this CVE cannot be triggered in
our build. No Echo patch is required. Re-evaluate if this spec is ever
rebased to coreutils >= 9.11.