Just adding some information on how to validate if the provisioning profile is afflicted by this.
To validate the provisioning profile ZZZ.mobileprovisionwe can use openssl or other tools to check the digital signature of the file itself, searching for the validity of the certificates that have signed the provisioning profile.
openssl pkcs7 -print_certs -text -in ZZZ.mobileprovision -inform der
That will output the full information of the certificates. This should be a rather big output with many details about the certificates. These afflicted files should have been signed by at least 1 of the expired certificates:
EXPIRED Subject: C=US, O=Apple Inc., OU=Apple Certification Authority, CN=Apple iPhone Certification Authority
EXPIRED Subject: C=US, O=Apple Inc., CN=Apple iPhone OS Provisioning Profile Signing
Subject: C=US, O=Apple Inc., OU=Apple Certification Authority, CN=Apple Root CA