Xfig: xfig: stack-overflow allows possible code execution via local input manipulation (CVE-2025-46397) | HOL Guard CVE