paxdecodeheader in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.32"
}
]
}