PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107696 FFmpeg CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T17:30:27.515Z and has not been modified since then. The vulnerability allows attackers controlling an RTSP server to cause endless reconnects, potentially saturating a CPU core. Defenders managing RTSP servers or clients using FFmpeg through 9.0.2 should assess exposure and prioritize patching to prevent potential CPU core saturation attacks. The vulnerability is in ff_rtsp_connect() in libavformat/rtsp.c, which follows RTSP 3xx redirects without a limit.

Vendor
FFmpeg
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders managing RTSP servers or clients using FFmpeg through 9.0.2 should assess exposure and prioritize patching to prevent potential CPU core saturation attacks. This includes reviewing compensating controls, monitoring for potential RTSP redirect attacks, and tracking exceptions. The vulnerability can impact service availability and potentially lead to service disruption or compromise.

Why it matters

Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability. The vulnerability allows attackers to cause infinite loops, potentially leading to service disruption or compromise.

  • CPU core saturation via endless reconnects
  • Potential RTSP server or client compromise
  • Service availability impact due to infinite loops

Technical summary

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c. This vulnerability allows attackers controlling an RTSP server to cause endless reconnects, potentially saturating a CPU core. The vulnerability follows RTSP 3xx redirects without a limit, which can lead to service disruption or compromise. Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability. The vulnerability has been patched in FFmpeg pull request 24902.

Defensive priority

Defenders should prioritize verifying exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability.

Recommended defensive actions

  • Verify exposure in RTSP server and client deployments
  • Assess CPU core saturation risk in affected systems
  • Apply patch from FFmpeg pull request 24902
  • Monitor for potential RTSP redirect attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on an infinite loop vulnerability in FFmpeg through 9.0.2. The vulnerability is in ff_rtsp_connect() in libavformat/rtsp.c, which follows RTSP 3xx redirects without a limit, potentially causing CPU core saturation. The source item and CVE record provide evidence of the vulnerability and its potential impact. Defenders should verify exposure in RTSP server and client deployments, especially where CPU core saturation could impact service availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107696 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107696

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107696 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107696

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107696.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/rtsp.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://gist.github.com/OxBat/648a0bd60c898f2ffb418e131ce26013

    Supplemental source - exploit

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-infinite-loop-via-rtsp-redirect-handling-in-rtsp-c

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.