cbcvebase.
CVE-2024-36615
published 2024-11-29

CVE-2024-36615: FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.44%
35.7th percentile
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianffmpeg< ffmpeg 7:4.3.9-0+deb11u2 (bullseye)ffmpeg 7:4.3.9-0+deb11u2 (bullseye)
ffmpegffmpeg
ffmpegffmpeg>= 0 < 7:4.3.9-0+deb11u27:4.3.9-0+deb11u2
ffmpegffmpeg>= 0 < 7:7.1-37:7.1-3
ffmpegffmpeg>= 0 < 7:7.1-37:7.1-3

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.