In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-52625.json"