SECURITY UPDATE: Certificate policy bypass via case-sensitive nameConstraints
debian/patches/CVE-2026-3833.patch: replace memcmp with c_strncasecmp in
ends_with, email_ends_with, dnsname_matches and email_matches in
lib/x509/name_constraints.c so DNS labels and email domains are compared
case-insensitively per RFC 5280 7.2