OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=30908
Crash type: Heap-buffer-overflow READ 2
Crash state:
OT::OffsetTo<OT::Anchor, OT::IntType<unsigned short, 2u>, true>* hb_serialize_co
OT::OffsetTo<OT::Anchor, OT::IntType<unsigned short, 2u>, true>* hb_serialize_co
bool OT::AnchorMatrix::serialize<hb_filter_iter_t<hb_range_iter_t<unsigned int,