Use-after-free / double-free of the root USB device in the experimental USB host stack (CVE-2026-10663) | HOL Guard CVE