Incus has arbitrary file read+write on host via templates/ symlink in malicious image (CVE-2026-48752) | HOL Guard CVE