A use-after-free vulnerability was found in Collator::sortWithSortKeys, that can be potentially remotely exploitable if the sorting function is called on a user supplied array. Only php 7 is affected.
Upstream bug (contains reproducer resulting into null dereference):
https://bugs.php.net/bug.php?id=71020
CVE assignment:
http://seclists.org/oss-sec/2015/q4/561