http://cgit.freedesktop.org/fontconf...b01cd7d5121507 may exist on 5.6.1.1. The code was removed in the version on 5.6.5. It may have been stealth fixed from 5.6.1.1 to 5.6.5 and may still be present. I didn't bother looking due to 5.6.5 not being vulnerable.
Would be trivial to exploit if present. Left as an exercise to the reader.