bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max (CVE-2026-93125) | HOL Guard CVE