tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter (CVE-2025-54798) | HOL Guard CVE