PatchSiren cyber security CVE debrief
CVE-2026-107696 FFmpeg CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T17:30:27.515Z and has not been modified since then. The vulnerability allows attackers controlling an RTSP server to cause endless reconnects, potentially saturating a CPU core. Defenders managing RTSP servers or clients using FFmpeg through 9.0.2 should assess exposure and prioritize patching to prevent potential CPU core saturation attacks. The vulnerability is in ff_rtsp_connect() in libavformat/rtsp.c, which follows RTSP 3xx redirects without a limit.
- Vendor
- FFmpeg
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders managing RTSP servers or clients using FFmpeg through 9.0.2 should assess exposure and prioritize patching to prevent potential CPU core saturation attacks. This includes reviewing compensating controls, monitoring for potential RTSP redirect attacks, and tracking exceptions. The vulnerability can impact service availability and potentially lead to service disruption or compromise.
Why it matters
Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability. The vulnerability allows attackers to cause infinite loops, potentially leading to service disruption or compromise.
- CPU core saturation via endless reconnects
- Potential RTSP server or client compromise
- Service availability impact due to infinite loops
Technical summary
FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c. This vulnerability allows attackers controlling an RTSP server to cause endless reconnects, potentially saturating a CPU core. The vulnerability follows RTSP 3xx redirects without a limit, which can lead to service disruption or compromise. Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability. The vulnerability has been patched in FFmpeg pull request 24902.
Defensive priority
Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability.
Recommended defensive actions
- Verify exposure in RTSP server and client deployments
- Assess CPU core saturation risk in affected systems
- Apply patch from FFmpeg pull request 24902
- Monitor for potential RTSP redirect attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on an infinite loop vulnerability in FFmpeg through 9.0.2. The vulnerability is in ff_rtsp_connect() in libavformat/rtsp.c, which follows RTSP 3xx redirects without a limit, potentially causing CPU core saturation. The source item and CVE record provide evidence of the vulnerability and its potential impact. Defenders should verify exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107696 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107696
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107696 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107696
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107696.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/rtsp.c
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/OxBat/648a0bd60c898f2ffb418e131ce26013
Supplemental source - exploit
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-infinite-loop-via-rtsp-redirect-handling-in-rtsp-c
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.