Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-123

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale h...

JLSEC Published
Modified
Affected Packages
FFMPEG_jll < 6.1.1+0
FFplay_jll < 7.1.0+0
Aliases / Upstream
CVE-2022-48434

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

References