fix CVE-2026-25646: heap buffer overflow in png_set_quantize

Source: Fedora 42 libpng12 Important Heap Overflow Fix CVE-2026-25646