PocketSphinx: Buffer overflows in language and acoustic model loading code (CVE-2026-54559) | HOL Guard CVE