squashfs-tools is vulnerable to directory traversal. The vulnerability exists due to the reusing of filename which is in turn not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
bugs.launchpad.net/ubuntu/+source/squashfs-tools/+bug/1941790
github.com/plougher/squashfs-tools/commit/79b5a555058eef4e1e7ff220c344d39f8cd09646
github.com/plougher/squashfs-tools/issues/72
lists.debian.org/debian-lts-announce/2021/08/msg00030.html
lists.fedoraproject.org/archives/list/[email protected]/message/GSMRKVJMJFX3MB7D3PXJSYY3TLZROE5S/
lists.fedoraproject.org/archives/list/[email protected]/message/RAOZ4BKWAC4Y3U2K5MMW3S77HWWXHQDL/
security-tracker.debian.org/tracker/CVE-2021-40153
www.debian.org/security/2021/dsa-4967