CVE-2024-36615 Information
Dec 01, 2024
cve
Description
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported as the side data would be attached in the decoder thread while being read in the output thread.
Reference
https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738 https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61
Share on: