OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) (CVE-2026-65979) | HOL Guard CVE