CVE-2024-36615: Ffmpeg

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

Affected products

  • Ffmpeg Ffmpeg: version 7.0 only

Published 2024-11-29. Last modified 2026-06-17.