This vulnerability is disputed by the opensh maintainers and is considered
expected behavior.
https://security-tracker.debian.org/tracker/CVE-2016-20012
https://github.com/openssh/openssh-portable/pull/270
https://www.openwall.com/lists/oss-security/2018/08/24/1