Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref (CVE-2026-10653) | HOL Guard CVE