Bluetooth: L2CAP: validate option length before reading conf opt value (CVE-2026-64403) | HOL Guard CVE