CVE-2026-23307 can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message