I don't see it committed in the master, so I am adding the patch from debian BT in case you are inclined to include it: https://sources.debian.org/patches/eterm/0.9.6-7/CVE-2021-33477.patch/