Unrated severityNVD Advisory· Published Sep 24, 2026
CVE-2026-88383
CVE-2026-88383
Description
libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.
Affected products
1- Range: <4.0.6
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.