Microsoft Security Response Center 中文 关注 CVE-2026-38754 Busybox v1.38.0 中 ifsbreakup() 函数(shell/ash.c)存在堆溢出漏洞,攻击者可通过提供精心构造的输入引发拒绝服务(DoS)。” CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. msrc.microsoft.com