Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_register (CVE-2026-13213) | HOL Guard CVE