yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied) (CVE-2026-25706) | HOL Guard CVE