AZL-106797

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106797.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106797
Upstream
  • CVE-2026-88383
Published
2026-09-24T17:17:07Z
Modified
2026-10-10T05:36:40Z
Summary
CVE-2026-88383 affecting package libical 3.0.10-1
Details

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.

References

Affected packages

Azure Linux:3 / libical

Package

Name
libical
Purl
pkg:rpm/azure-linux/libical

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.0.10-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106797.json"