OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize (CVE-2026-54920) | HOL Guard CVE