Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encryption (CVE-2026-96747) | HOL Guard CVE