Using ubsan and afl, I found that pointer arithmetic may be carried out on a null pointer, which is undefined behaviour. See #1442 for code to reproduce it.