Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-36615


FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.


Published

2024-11-29T19:15:07.703

Last Modified

2025-06-03T16:05:03.440

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ffmpeg ffmpeg 7.0 Yes

References