libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write (CVE-2026-50538) | HOL Guard CVE