PT-2024-27095 · FFmpeg+1 · Ffmpeg+1

Published

2024-11-29

·

Updated

2025-06-03

·

CVE-2024-36615

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FFmpeg version n7.0
Description The issue is related to a race condition in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
Recommendations For FFmpeg version n7.0, as a temporary workaround, consider disabling the VP9 decoder until a patch is available. Restrict access to video encoding parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2024-36615
OPENSUSE-SU-2025:15177-1

Affected Products

Debian
Ffmpeg