app-arch/tar: fixing cve-2022-48303

This patch fixes an out of band read in tar which resolves
CVE-2022-48303.

BUG=b/269587296
TEST=presubmit
RELEASE_NOTE="Fixed CVE-2022-48303 in app-arch/tar"

cos-patch: security-high
Change-Id: I9e951e2472bfc9c55fcb6cc0c8b596b7a983c87f
Reviewed-on: https://cos-review.googlesource.com/c/third_party/overlays/portage-stable/+/43908
Reviewed-by: Meena Shanmugam <meenashanmugam@google.com>
Tested-by: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
Main-Branch-Verified: Cusky Presubmit Bot <presubmit@cos-infra-prod.iam.gserviceaccount.com>
2 files changed