FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | May 15, 2025 | Nov 29, 2024 |
| Ffmpeg | — | Upgrade to FFmpeg version 7.1 | Jun 5, 2025 | Nov 29, 2024 |
| Suse | — | Upgrade libavformat61Upgrade libavutil59Upgrade libavcodec61Upgrade libavdevice61Upgrade libpostproc58Upgrade ffmpeg-7Upgrade libswresample5Upgrade libavfilter10Upgrade libswscale8 | Dec 5, 2025 | May 31, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub