Many security fixes:
CVE-2025-13763: Several uses of potentially uninitialized memory detected by fuzzers
CVE-2025-49010: Possible write beyond buffer bounds during processing of GET RESPONSE APDU
CVE-2025-66215: Possible write beyond buffer bounds in oberthur driver
CVE-2025-66038: Possible read beyond buffer bounds when parsing historical bytes in PIV driver
CVE-2025-66037: Possible buffer overrun while parsing SPKI
More low-severity data handling issues when parsing profile configuration
This commit was created by a combination of scripts and tools:
- an ast-grep script to prefix things in meta with `lib.`,
- a modified nixf-diagnose / nixf combination to remove unused `with
lib;`, and
- regular nixfmt.
Co-authored-by: Wolfgang Walther <walther@technowledgy.de>