libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.
CVE-2026-88383
NONE
EPSS 0.17%
Updated Sep 25, 2026
libical
CVE Details
CVE ID
CVE-2026-88383
Published Date
Sep 24, 2026
Vendor
libical
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
5.3th percentile (higher than 5.3% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory