Fix heap OOB read in RNN operator via sequence_lens=0 (#28052)
### Description
In the CPU RNN operator's \\Assign_Y_h\\ function, when
\\sequence_lens\\ contains a value of 0, the computation
\\sequence_lens[batch] - 1 = -1\\ produces a negative offset into the Y
output buffer. \\CopyVector\\ then reads \\hidden_size\\ floats from
heap memory before the buffer, leaking heap data into the \\Y_h\\ output
tensor.
LSTM and GRU already handle zero-length sequences correctly (early
return + zero-fill in compute path), but the basic RNN operator had
neither protection.
### Changes
- **rnn.cc \\Compute()\\**: Add early return when \\max_sequence_length
== 0\\ — zero-fills Y and Y_h outputs and returns immediately (matches
existing LSTM/GRU pattern)
- **rnn.cc \\Assign_Y_h()\\**: Add bounds check on \\last_time_step\\
before computing buffer offset — guards against both negative index
(\\seq_lens=0\\) and index >= seq_length, zero-fills Y_h for invalid
entries
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>