smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() (CVE-2026-89633) | HOL Guard CVE