A heap-based out-of-bounds memory read has been encountered in FreeType. It has been reproduced with the current version of freetype2 from master git branch, with a 64-bit build of the ftbench utility compiled with AddressSanitizer. Three proof of concepts are included.
98e8c4be3dc2aa55e2297273a7742b8e6dc7aafc1c27074f4f27654b18bf445e