There is no need to upgrade using backports, that vulnerability is already fixed in current versions.
Vulnerable and fixed packages
| Source Package | Release | Version | Status |
|---|---|---|---|
| openssh (PTS) | bullseye | 1:8.4p1-5+deb11u3 | fixed |
| bullseye (security) | 1:8.4p1-5+deb11u5 | fixed | |
| bookworm | 1:9.2p1-2+deb12u7 | fixed | |
| bookworm (security) | 1:9.2p1-2+deb12u5 | fixed | |
| trixie | 1:10.0p1-7 | fixed | |
| forky, sid | 1:10.2p1-3 | fixed |
More info: