SECURITY UPDATE: global buffer overflow read in UIL and XPM encoders.
debian/patches/CVE-2026-25898.patch: clamp negative pixel index values
to zero in WriteUILImage, WritePICONImage, and WriteXPMImage before
using them as array subscripts into the Cixel table.