Home
Description
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
References
github.com/...ommit/0ba058579f332b3060d8470a04ddd3fbf305be61
github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c