CVE-2026-88383

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.

  • Published Sep 24, 2026
  • Not yet scored
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2026-88383 at the National Vulnerability Database