OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=11010
Crash type: Global-buffer-overflow READ 1
Crash state:
BEInt<unsigned short, 2>::operator unsigned short
AAT::ContextualSubtable::driver_context_t::transition
void AAT::StateTableDriver<AAT::ContextualSubtable::EntryData>::drive<AAT::Conte