KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context (CVE-2026-80699) | HOL Guard CVE