Double free vulnerability when calling SplDoublyLinkedList::offsetSet and passing in an invalid index was found allowing to gain code execution. Upstream bug: https://bugs.php.net/bug.php?id=71735 Upstream patch: http://git.php.net/?p=php-src.git;a=commit;h=28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5
Only PHP 7 was affected by this issue.