CVE-2020-25710: Debian Linux

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 33 only
  • Openldap Openldap: before 2.4.56 (fixed in 2.4.56)
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat JBoss Core Services: affected versions not specified
  • Red Hat JBoss Enterprise Application Platform: version 5.0.0 only
  • Red Hat JBoss Enterprise Web Server: version 2.0.0 only

Published 2021-05-28. Last modified 2026-06-17.