OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow origin (CVE-2026-59189) | HOL Guard CVE