CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd