CVE-2020-36221: Apple Mac OS X

High severity, CVSS 7.5. EPSS: 85% chance of exploitation in the next 30 days.

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

Affected products

  • Apple Mac OS X: from 10.14.0, before 10.14.6 (fixed in 10.14.6); version 10.14.6 only
  • Apple macOS: from 11.1, before 11.4 (fixed in 11.4)
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Openldap Openldap: before 2.4.57 (fixed in 2.4.57)

Published 2021-01-26. Last modified 2026-06-17.