tar has had some mitigations for this since 1999, it would be nice to mention in the docs that this is not a new bug. e.g. CVE-2016-6321 is example, and so is https://www.mobileread.com/forums/showpost.php?p=1902438&postcount=41