OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow (CVE-2026-44663) | HOL Guard CVE