I assume they mean the latest version available for download as an .iso, since I think that tends to happen around monthly. I agree that this isn't super concerning though, since even installing from that would result in an up-to-date system, and there isn't much reason to ssh to or from the live disk.
> OpenSSH server (sshd) 9.1 introduced
https://security-tracker.debian.org/tracker/CVE-2023-25136
Is this even exploitable in any distributed configuration, considering that it requires enabling old deprecated key exchange algorithms?