Patch was added d95a0b0706, apparently based on the one discussed in [1], but using ERROR instead of FATAL_ERROR. However, per [2], this was fixed in another way, though upstream seems to not consider it worthy of a CVE. [1] https://lists.gnu.org/archive/html/bug-tar/2016-10/msg00014.html [2] https://lists.gnu.org/archive/html/bug-tar/2016-10/msg00016.html
d95a0b0706