CVE-2020-36221

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-36221

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-36221.html

OS impact

OSVersionStatusFixed in
arch archfixed2.4.57-1
suse slesaffected
debian debianbookwormfixed2.4.57+dfsg-1
debian debianbullseyefixed2.4.57+dfsg-1
debian debianforkyfixed2.4.57+dfsg-1
debian debiansidfixed2.4.57+dfsg-1
debian debiantrixiefixed2.4.57+dfsg-1

References

Verify integrity in audit chain (admin only). AS-IS.