Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries (CVE-2026-26158) | HOL Guard CVE