Vulnerability record · CVE-2020-36221 · published 26 January 2021
CVE-2020-36221: OpenLDAP slapd integer underflow crashes on Certificate Exact Assertion
Openldap · Openldap
OpenLDAP before 2.4.57 contains an integer underflow in slapd's Certificate Exact Assertion processing (schema_init.c serialNumberAndIssuerCheck). A crafted certificate assertion triggers the underflow and crashes the daemon, causing denial of service. The flaw is remotely reachable without authentication, so any exposed LDAP service is at risk of repeated outages.
Description
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with a very high EPSS score, though no KEV listing or documented exploitation.
What it is
OpenLDAP before 2.4.57 contains an integer underflow in slapd's Certificate Exact Assertion processing (schema_init.c serialNumberAndIssuerCheck). A crafted certificate assertion triggers the underflow and crashes the daemon, causing denial of service. The flaw is remotely reachable without authentication, so any exposed LDAP service is at risk of repeated outages.
Impact
An attacker can crash slapd, taking down directory authentication and any services that depend on it. No data confidentiality or integrity loss is described; the effect is availability only.
Attack surface
Reached over the network via the LDAP service (CVSS vector AV:N/AC:L/PR:N/UI:N), with no authentication or user interaction required. The vulnerable path is Certificate Exact Assertion processing in slapd.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high (0.842 probability, 99.7th percentile), indicating elevated likelihood of attempted exploitation. References are patches, vendor advisories and third-party advisories only.
What to do
- Upgrade OpenLDAP to 2.4.57 or later, applying the vendor commits 38ac838e and 58c1748e.
- Apply the Debian DSA-4845 and Apple security updates for affected packages and macOS builds.
- Restrict network access to slapd so only trusted clients can reach the LDAP listener.
- Monitor slapd for unexpected restarts and alert on crash loops.
Detection
- Watch for slapd process crashes or restarts correlated with inbound LDAP traffic.
- Inspect LDAP requests containing Certificate Exact Assertion filters for malformed or unusual serialNumber/issuer values.
- Baseline normal LDAP query patterns and alert on anomalous assertion-based searches from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-36221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-36221), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.