Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) | HOL Guard CVE