FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
CVSS
No CVSS.
References
Configurations
History
03 Jun 2025, 16:05
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ffmpeg ffmpeg
Ffmpeg |
|
CPE | cpe:2.3:a:ffmpeg:ffmpeg:7.0:*:*:*:*:*:*:* | |
References | () https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb - Third Party Advisory | |
References | () https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738 - Product | |
References | () https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61 - Patch |
29 Nov 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-29 19:15
Updated : 2025-06-03 16:05
NVD link : CVE-2024-36615
Mitre link : CVE-2024-36615
JSON object : View
Products Affected
ffmpeg
- ffmpeg
CWE
No CWE.