Ah, gotcha. You're not trying to gracefully grandfather in those whose passwords are affected. Rather, you're simply forcing their passwords to be invalid once you have the corrected library.
That leaves the process of "how do you securely reset the affected users' passwords" as an exercise to be solved by the reader. ;-)