Impact
The vulnerability is a double‑free in the CalDAV worker when a PATCH request containing PATCH‑ACTION="BYPARAM@…" is processed for a calendar resource that has two or more properties of the matched kind. The flaw is triggered only by an authenticated calendar user and results in the selector memory being freed twice, causing the CalDAV worker to crash. This leads to a denial of service; the description does not indicate any data disclosure or code execution.
Affected Systems
The affected vendor is Cyrus IMAP. Versions before 3.12.4 are impacted, including releases 3.8.8, 3.10.4 and earlier 3.12.x builds.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with calendar write access to send a crafted PATCH request. Because the flaw only causes a process crash, the impact is limited to the CalDAV worker and may require a service restart, but it presents a realistic threat in environments where such users exist.
OpenCVE Enrichment