OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20944
Crash type: Heap-buffer-overflow READ 2
Crash state:
BEInt<unsigned short, 2>::operator unsigned short
OT::IntType<unsigned short, 2u>::operator unsigned int
OT::gvar::get_offset