Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough (CVE-2026-18495) | HOL Guard CVE