CVE-2026-31616 usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()