Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (CVE-2026-59197) | HOL Guard CVE