OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=11060
Crash type: Heap-buffer-overflow READ 1
Crash state:
BEInt<unsigned short, 2>::operator unsigned short
AAT::LookupFormat10<OT::IntType<unsigned int, 4u> >::sanitize
AAT::Lookup<OT::IntType<unsigned int, 4u> >::sanitize