Home
Description
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
References
github.com/...ommit/0ba058579f332b3060d8470a04ddd3fbf305be61
github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c
gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb