OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length (CVE-2026-55371) | HOL Guard CVE