CVE-2026-88383

Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.

Published 2026-09-24. Last modified 2026-10-06.