hhvm before 3.12.11 has a use-after-free in the serializememoizeparam() and ResourceBundle::__construct() functions.
{ "binaries": [ { "binary_version": "3.11.1+dfsg-1ubuntu1", "binary_name": "hhvm" }, { "binary_version": "3.11.1+dfsg-1ubuntu1", "binary_name": "hhvm-dev" } ] }