SECURITY UPDATE: GSS-API resource leak triggered by multi-round TKEY
debian/patches/CVE-2026-3039.patch: reject GSS_S_CONTINUE_NEEDED in
dst_gssapi_acceptctx() and release the partial security context
and gouttoken so they don't accumulate per malicious TKEY query.