CVE-2024-36615
published 2024-11-29CVE-2024-36615: FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.44%
35.7th percentile
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:4.3.9-0+deb11u2 (bullseye) | ffmpeg 7:4.3.9-0+deb11u2 (bullseye) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u2 | 7:4.3.9-0+deb11u2 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1-3 | 7:7.1-3 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1-3 | 7:7.1-3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FFmpeg 7.0 VP9 Decoder race condition (Nessus ID 239902 / WID-SEC-2024-3572)
vuldb·2026-06-22·CVSS 5.9
CVE-2024-36615 [MEDIUM] FFmpeg 7.0 VP9 Decoder race condition (Nessus ID 239902 / WID-SEC-2024-3572)
A vulnerability marked as problematic has been reported in FFmpeg 7.0. This affects an unknown function of the component VP9 Decoder. Performing a manipulation results in race condition.
This vulnerability is reported as CVE-2024-36615. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
OSV
CVE-2024-36615: FFmpeg n7
osv·2024-11-29·CVSS 5.9
CVE-2024-36615 [MEDIUM] CVE-2024-36615: FFmpeg n7
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
GHSA
GHSA-9fr3-g426-jq79: FFmpeg n7
ghsa_unreviewed·2024-11-29
CVE-2024-36615 [MEDIUM] CWE-362 GHSA-9fr3-g426-jq79: FFmpeg n7
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
Debian
CVE-2024-36615: ffmpeg - FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could le...
vendor_debian·2024·CVSS 5.9
CVE-2024-36615 [MEDIUM] CVE-2024-36615: ffmpeg - FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could le...
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7:4.3.9-0+deb11u2)
forky: resolved (fixed in 7:7.1-3)
sid: resolved (fixed in 7:7.1-3)
trixie: resolved (fixed in 7:7.1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-29
Published