capabilities: simplify bound checks for copy_from_user()