Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
https://usn.ubuntu.com/3935-1/
https://lists.debian.org/debian-lts-announce/2021/02/msg00020.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00037.html